CVE-2019-12868
18.06.2019, 00:15
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.Enginsight
Vendor | Product | Version |
---|---|---|
misp | misp | 2.4.109 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References