Vulnerabilities > CVE-2020-15412 - Missing Authorization vulnerability in Misp 2.4.128

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
misp
CWE-862

Summary

An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.

Vulnerable Configurations

Part Description Count
Application
Misp
1

Common Weakness Enumeration (CWE)