ICE2-8IOL1-G65L-V1D vulnerability

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

Published 16 Sep 2026Updated 19 Sep 20263 sources
CVSS 6.5

Source timeline

CVE record published by NVDView source ↗