IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 allow a user to alter values in the database via manipulated API requests. Version 2.4.28 contains a patch.
https://github.com/dfir-iris/iris-web/security/advisories/GHSA-w78h-mx7h-qm3h