Impact
The vulnerability exposes several controller actions in MISP that can be invoked by a GET request made under an authenticated session. Because GET requests can be induced cross‑origin through links, images, redirects, or navigation, an attacker can trigger these actions with the victim’s authenticated session.
Affected Systems
The affected vendor is MISP, and the product is the MISP platform. Versions up to and including 2.5.45 are impacted. Users should check that their installation is on a release newer than 2.5.45.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity, and the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a classic CSRF attack that relies on a malicious web page or embedded content to make a GET request to a state‑changing endpoint while the victim is logged into MISP.
OpenCVE Enrichment