Описание
An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.
Ссылки
- Patch
- Release Notes
- Patch
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 2.4.184 (исключая)
cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
EPSS
Процентиль: 30%
0.00108
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-749
Связанные уязвимости
CVSS3: 9.8
github
почти 2 года назад
An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.
EPSS
Процентиль: 30%
0.00108
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-749