Improper Privilege Management in MISP - CVE-2019-16202
Published: September 10, 2019 / Updated: July 17, 2020
MISP
Detailed vulnerability description
The vulnerability allows a remote authenticated user to gain access to sensitive information.
MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115)" message.