Impact
The vulnerability originates from an incorrect operator‑precedence in a conditional that controls whether external XML can be fetched. When the readFile option is set to false, the logic still allows URLs that begin with https:// to be fetched, causing the library to issue an outbound HTTPS request. The fetched content is parsed as XML and may be returned to the caller, resulting in disclosure of internal or external data. This is a classic server‑side request forgery with an information‑disclosure impact.
Affected Systems
The exposed code resides in the MISP sachertortephp library, specifically the Xml::build() static method in lib/Cake/Utility/Xml.php. Any deployment that includes sachertortephp and passes reach‑able input to Xml::build() while setting readFile to false is susceptible. The exact version range impacted is not detailed in the data, so consider all versions prior to the commit that applied the fix as vulnerable.
Risk and Exploitability
The CVSS score for this flaw is 5.1, indicating a moderate severity. No EPSS score is provided, making it difficult to assess current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack requires that an attacker can influence the $input string and that the caller disables readFile, which is feasible in many dynamic XML parsing scenarios. The compromise is limited to informational disclosure via HTTPS SSRF and does not enable arbitrary code execution, but it can still be leveraged to exfiltrate sensitive data from internal services.
OpenCVE Enrichment