CVE-2024-46918

MEDIUM

Misp < 2.4.198 - Incorrect Authorization

Title source: rule
STIX 2.1

Description

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

Scores

CVSS v3 4.9
EPSS 0.0010
EPSS Percentile 28.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
misp/misp < 2.4.198
Published Sep 15, 2024
Tracked Since Feb 18, 2026