CVE-2018-8949: Misp-Project Misp
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) could overwrite an existing attribute.
Affected products
- Misp-Project Misp: before 2.4.89 (fixed in 2.4.89)
Published 2018-03-23. Last modified 2026-06-17.