CyberRota Analysis
AI-GeneratedAffected versions of MISP cti-transmute expose critical state-changing account operations through GET requests, making them vulnerable to cross-site request forgery (CSRF) attacks. This vulnerability allows an attacker to exploit the victim's authenticated session to perform actions such as following accounts or deleting notifications without their consent. Organizations using this software should prioritize applying the patch to mitigate potential unauthorized account manipulations.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /account/follow * /account/delete_notification * /account/mark_notification_read * /account/mark_all_read These endpoints require authentication, but before the fix they could be invoked with simple GET requests. That makes them susceptible to cross-site request forgery because a third-party site can induce the victim’s browser to send authenticated GET requests automatically. The patch converts the actions to POST or DELETE and updates the frontend to include an X-CSRFToken header, providing explicit CSRF protection for those state-changing operations.