CVE-2019-9482: Misp-Project Misp

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).

Affected products

Published 2019-03-01. Last modified 2026-06-22.