PT-2026-38309 · Unknown · Misp-Modules

Published

2026-05-06

·

Updated

2026-05-13

·

CVE-2026-44364

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions MISP modules versions 3.0.7 and earlier
Description A Cross-Site Request Forgery (CSRF) issue in the MISP Modules website allows an attacker to trick an authenticated user into submitting unintended requests to the "/home" endpoint. This occurs because the home blueprint is exempted from CSRF protection, potentially enabling the modification of session query data within the authenticated user's context.
Recommendations Update to a version later than 3.0.7 to enable CSRF protection for the affected blueprint and implement hardened query parsing.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-44364
GHSA-J4RH-7JCR-QM69

Affected Products

Misp-Modules