PT-2026-96717 · Misp+1 · Misp+1
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.47
Description
The
WorkflowsController exposes the moduleStatelessExecution action within the Security component's unlockedActions list. In the CakePHP framework, including an action in unlockedActions disables field hash validation and Cross-Site Request Forgery (CSRF) token checks. Since moduleStatelessExecution triggers a workflow module's exec() function using input and parameters provided by the caller, an attacker can craft a cross-site form post or cross-origin request. If an authenticated site administrator submits this request, it triggers the action on the MISP instance, allowing the attacker to execute any workflow module, including those that modify blocklist and warninglist entries, with arbitrary parameters.Recommendations
Update to version 2.5.47.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cakephp
Misp