Vulnerabilities > CVE-2015-5719 - Unspecified vulnerability in Misp-Project Malware Information Sharing Platform
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.
Vulnerable Configurations
References
- http://www.securityfocus.com/bid/92740
- http://www.securityfocus.com/bid/92740
- https://github.com/MISP/MISP/commit/27cc167c3355ec76292235d7f5f4e0016bfd7699
- https://github.com/MISP/MISP/commit/27cc167c3355ec76292235d7f5f4e0016bfd7699
- https://www.circl.lu/advisory/CVE-2015-5719/
- https://www.circl.lu/advisory/CVE-2015-5719/