PT-2026-96093 · Misp · Misp
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.47
Description
An insecure direct object reference exists in the
processModuleResultsData() function of the Event model. When processing module results, the system fails to unset the client-supplied id field for EventReport entries before saving. Since the create() method of the EventReport model does not strip this field, an authenticated user with permissions to submit module results can provide an id referencing a report from a different event. This allows the user to bypass authorization to read the content of another event's report by reparenting it, overwrite report fields with controlled data, or change the event id to redirect ownership, leading to cross-event data disclosure and integrity compromise.Recommendations
Update to version 2.5.47 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Misp