GHSA-w4vp-6x5p-cm7mHighCVSS 7.5

An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can...

Published
April 22, 2022
Last Modified
June 22, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

🔗 References (6)