Impact
The vulnerability is rooted in improper input validation (CWE‑20) and cross‑352). An attacker can override the HTTP method used by CakePHP to a non‑write verb such as GET, causing the framework to clear the request body. Because MISP’s security logic checks for performing CSRF and form validation, an empty body causes these protections to be skipped entirely. A crafted form or request that only changes the '_method' field or 'X-HTTP-Method-Override' header can therefore reach actions that rely on URL parameters, enabling an attacker to execute unintended operations without CSRF tokens or form validation.
Affected Systems
Affected versions are MISP 2.5.45 and earlier. The offending code path resides in MISP’s BetterSecurityComponent, which is used by all MISP installations built on CakePHP.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score of less than 1% suggests that widespread exploitation is unlikely, and MISP is not listed in the CISA KEV catalogue. The attack vector is a web‑based request or cross‑site form that supplies an '_method' value or 'X-HTTP-Method-Override' header outside the allowed set. Successful exploitation would allow an attacker to bypass CSRF protection and send unauthorized requests to MISP endpoints that accept URL‑based parameters.
OpenCVE Enrichment