CVE-2015-5719: Critical severity Misp-project Malware Information Sharing Platform vulnerability
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MISP - Malware Information Sharing Platformto a version that resolves this vulnerability.Fixed in 2.3.92
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5719?
CVE-2015-5719 is classified as a medium severity vulnerability due to improper filename restrictions.
How do I fix CVE-2015-5719?
To fix CVE-2015-5719, upgrade the Malware Information Sharing Platform to version 2.3.92 or later.
What impact does CVE-2015-5719 have on system security?
CVE-2015-5719 can lead to file manipulation and potential unauthorized access to sensitive information.
Which versions of MISP are affected by CVE-2015-5719?
CVE-2015-5719 affects all versions of MISP prior to 2.3.92.
Is CVE-2015-5719 publicly known?
Yes, CVE-2015-5719 is a publicly disclosed vulnerability.