MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.
As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:
- Read the thread title and the content of the quoted post
- Submit a new post into the discussion thread
This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in). Affected: <2.5.48
Характеристики атаки
Последствия
Строка CVSS v4.0