#VU25633 Improper access control in MISP - CVE-2020-8894
Published: February 26, 2020
MISP
misp-project.org
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in app/Controller/ThreadsController.php and app/Model/Thread.php scripts. A remote authenticated attacker can bypass implemented security restrictions and view otherwise restricted discussions.