First published: Fri Sep 18 2020(Updated: )
An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MISP | <2.4.132 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25766 is an issue discovered in MISP before version 2.4.132, which allows performing an unwanted action by exploiting a POST operation on a form that is not linked to the login page.
The severity of CVE-2020-25766 is high with a CVSS score of 7.5.
CVE-2020-25766 affects MISP versions prior to 2.4.132.
To fix CVE-2020-25766, users should update to MISP version 2.4.132 or later.
You can find more information about CVE-2020-25766 at the following references: [link1](https://github.com/MISP/MISP/commit/164963100a830234744a6004d5eda55d24e97b2a) and [link2](https://github.com/MISP/MISP/compare/v2.4.131...v2.4.132).