Impact
MISP's Organisation model contains an authorization flaw. When the $force parameter is set to true, the captureOrg method overwrites organization metadata fields without checking user privileges. A user with sharing group editor rights can trigger this, allowing them to alter organization attributes that should be protected. The resulting integrity breach can change how sharing groups and blueprints behave across the MISP instance.
Affected Systems
This flaw affects the MISP platform, specifically the Organisation model used to store organization metadata. No version information is provided, so any installation of MISP where the captureOrg method is invoked with $force=true is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires an authenticated user with at least sharing group editor permissions and network access to the MISP web interface, implying an internal or compromised account. The vulnerability primarily threatens data integrity, but could influence sharing group configurations, making it a concern for security and operational stability.
OpenCVE Enrichment