A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-16 08:16
Updated : 2026-09-16 19:13
NVD link : CVE-2026-27553
Mitre link : CVE-2026-27553
CVE.ORG link : CVE-2026-27553
JSON object : View
Products Affected
No product.
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
