Password Confirmation Bypass in MISP by GRAAL Project
CVE-2022-29534
7.5HIGH
What is CVE-2022-29534?
In MISP versions prior to 2.4.158, a vulnerability exists within the UsersController.php that allows attackers to bypass password confirmation using specific request headers, such as 'Accept: application/json'. This can lead to unauthorized access and potential exploitation of user accounts, posing a significant risk to the integrity and security of the application. Users are strongly advised to upgrade to the latest version to mitigate this security issue.
