CVE-2024-46918: Critical severity Misp-project Misp vulnerability
Published Sep 15, 2024
·Updated
app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.
Affected Software
1 affected component
Misp-project Misp<2.4.198
Remediation
Patch Available
Event History
Sep 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-46918?
CVE-2024-46918 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-46918?
To fix CVE-2024-46918, upgrade MISP to version 2.4.198 or later.
3
What is the impact of CVE-2024-46918?
CVE-2024-46918 allows an organization admin to view sensitive login fields of another admin in the same organization.
4
Which versions of MISP are affected by CVE-2024-46918?
MISP versions prior to 2.4.198 are affected by CVE-2024-46918.
5
Can CVE-2024-46918 be exploited remotely?
CVE-2024-46918 requires authenticated access, making remote exploitation unlikely.