PT-2026-85456 · Misp · Misp
CVSS v4.0
6.2
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
A cross-site request forgery (CSRF) issue occurs because the system disables form-security and CSRF protections if a request is identified as REST traffic. This detection can be manipulated by an attacker using the HTTP Accept header (e.g.,
Accept: application/json), which can be sent from a cross-origin page without a CORS preflight. Consequently, the system may treat a request from a malicious website as REST traffic and bypass security validations while using the victim's authenticated browser session. An attacker could trick an authenticated user into visiting a malicious page to execute unauthorized state-changing requests to susceptible endpoints, potentially leading to the unauthorized modification, creation, publication, or removal of data. The issue stems from the isRest() function granting security exemptions based on request type rather than the authentication mechanism.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp