← Back to CVE List

CVE-2017-16946

Published: 2017-11-25T18:29Z
Last Modified: 2024-11-21T03:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt