Zurück zur CVE-Übersicht
CVE-2017-16946
MEDIUM(4.0)AV:N/AC:L/Au:S/C:P/I:N/A:N
Risk Signal Score10/100 — NIEDRIG
- CVSS 4 — Mittel
EPSS-Score
1%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
4
Technische Schwere
Beschreibung
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.