CVE-2018-19908
06.12.2018, 16:29
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.
Vendor | Product | Version |
---|---|---|
misp | misp | 2.4.90 ≤ 𝑥 < 2.4.99 |
𝑥
= Vulnerable software versions
References