Impact
A cross‑site request forgery flaw in the cullEmptyEvents action of MISP causes a state‑changing, irreversible operation when an authenticated user’s browser loads a crafted GET URL. Because CakePHP does not validate CSRF tokens on bodyless GET requests, an attacker can trigger the deletion of published empty events without any user interaction. The deletion skips blocklisting, so the removed events do not leave traces that could be used to track or prevent future synchronization, amplifying the destructive potential.
Affected Systems
The vulnerability affects MISP installations that have not applied the recent security fix. The CNA identifies the affected product as misp:misp; no specific version range is supplied, so all versions prior to the patch should be considered vulnerable until confirmed otherwise.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is classified as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but the attack requires an authenticated user’s credentials and access to a browser, meaning the threat surface is primarily internal or requires social engineering to convince a user to visit the malicious URL. Exploitation is straightforward once those prerequisites are met, and the impact is permanent loss of event data.
OpenCVE Enrichment