ICE2-8IOL1-G65L-V1D vulnerability

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

Published 16 Sep 2026Updated 19 Sep 20263 sources
CVSS 6.5

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.