CVE-2024-46918: Misp-Project Misp

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

Affected products

Published 2024-09-15. Last modified 2026-06-22.