Impact
The UserSettingsController in MISP was configured to skip all CSRF checks for the setTheme, setHomePage, and eventIndexColumnToggle actions. Because these endpoints accept POST requests that alter per‑user configuration, a malicious site can coerce an authenticated victim to send forged requests that change the victim’s theme, default home page, or event index column visibility. The most dangerous effect is setHomePage, which can redirect the user to an attacker‑controlled URL, enabling phishing or social‑engineering attacks. No authentication bypass is required; the user must already be logged in.
Affected Systems
Versions of MISP up to and including 2.5.45. The vulnerability was specifically noted for the MISP:MISP product line and is not limited to any particular deployment configuration.
Risk and Exploitability
The CVSS score of 5.1 indicates medium severity. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog. Attackers need to get a logged‑in user to load a malicious page that sends a POST request to one of the vulnerable endpoints. Because the actions were removed from CSRF validation, the forged request succeeds when the victim’s browser sends the request, but legitimate same‑origin requests continue to work under the new CSRF header‑only rule after applying the official fix.
OpenCVE Enrichment