app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.
References
Configurations
History
No history.
Information
Published : 2024-09-15 20:15
Updated : 2025-03-13 15:15
NVD link : CVE-2024-46918
Mitre link : CVE-2024-46918
CVE.ORG link : CVE-2024-46918
JSON object : View
Products Affected
misp
- misp
CWE
CWE-863
Incorrect Authorization