Improper access control in MISP - CVE-2020-8894
Published: February 26, 2020
MISP
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in app/Controller/ThreadsController.php and app/Model/Thread.php scripts. A remote authenticated attacker can bypass implemented security restrictions and view otherwise restricted discussions.