CVE-2018-8949: Misp-Project Misp

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) could overwrite an existing attribute.

Affected products

Published 2018-03-23. Last modified 2026-06-17.