Authorization Bypass in MISP's Bookmarks Controller
CVE-2024-45509
6.5MEDIUM
What is CVE-2024-45509?
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
