First published: Tue Jul 14 2020(Updated: )
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MISP | <2.4.129 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15711 is a vulnerability in MISP before 2.4.129 where setting a favorite homepage was not CSRF protected.
The severity of CVE-2020-15711 is high with a CVSS score of 8.8.
MISP versions up to and excluding 2.4.129 are affected by CVE-2020-15711.
To fix CVE-2020-15711, you should upgrade MISP to version 2.4.129 or later.
You can find more information about CVE-2020-15711 on the GitHub commit page: https://github.com/MISP/MISP/commit/bf4610c947c7dc372c4078f363d2dff6ae0703a8