CVE-2022-29534

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
5
MEDIUM
Affected
1
PROJECT

Description

An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

MISP (core software) - Open Source Threat Intelligence and Sharing Platform
GitHubGitHub
6.38K