Client-side vulnerability in MISP before 2.4.184 allows unauthorized export generation
CVE-2024-25675
9.8CRITICAL
What is CVE-2024-25675?
A significant security issue has been identified in MISP versions prior to 2.4.184, where the export generation process can be initiated by a client without the necessity of sending a POST request. This vulnerability impacts the application's JobsController.php and export.ctp files, potentially allowing unauthorized processes to commence. Users of MISP are encouraged to update to the latest version to mitigate any associated security risks.
