MISP 中的 动作存在跨站请求伪造(CSRF)漏洞。该端点在接受 HTTP GET 请求的同时,执行了具有状态变更且不可逆的操作。 由于不带请求体的 GET 请求不受 CakePHP 的 CSRF 校验保护,攻击者可以构造一个精心设计的 URL,例如通过嵌入的图片或其他自动加载的资源,诱导具有相应权限的已认证 MISP 用户的浏览器自动访问该端点,从而触发漏洞。 成功利用该漏洞会触发已发布空事件(empty events)的删除。这一删除操作具有特殊重要性,因为该操作使用了 ,意味着被删除的事件不会生成黑名单(b
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85216 | 9.5 CRITICAL | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials |
| CVE-2026-85237 | 8.6 HIGH | Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass |
| CVE-2026-85221 | 7.6 HIGH | MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attack |
| CVE-2026-85238 | 7.6 HIGH | Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking |
| CVE-2026-85239 | 7.1 HIGH | MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service |
| CVE-2026-85227 | 6.1 MEDIUM | Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAtta |
| CVE-2026-85226 | 5.3 MEDIUM | MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Co |
| CVE-2026-85230 | 5.3 MEDIUM | MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection |
No comments yet