PT-2026-38309 · Unknown · Misp-Modules
Published
2026-05-06
·
Updated
2026-05-13
·
CVE-2026-44364
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
MISP modules versions 3.0.7 and earlier
Description
A Cross-Site Request Forgery (CSRF) issue in the MISP Modules website allows an attacker to trick an authenticated user into submitting unintended requests to the "/home" endpoint. This occurs because the home blueprint is exempted from CSRF protection, potentially enabling the modification of session query data within the authenticated user's context.
Recommendations
Update to a version later than 3.0.7 to enable CSRF protection for the affected blueprint and implement hardened query parsing.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp-Modules