CVE-2015-5721: Code Injection
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populateeventfromtemplateattributes.ctp.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5721?
CVE-2015-5721 is considered a high severity vulnerability due to its potential for remote code execution through PHP object injection.
How do I fix CVE-2015-5721?
To fix CVE-2015-5721, upgrade the Malware Information Sharing Platform to version 2.3.90 or later.
What systems are affected by CVE-2015-5721?
CVE-2015-5721 affects all versions of the Malware Information Sharing Platform prior to 2.3.90.
Can CVE-2015-5721 lead to unauthorized access?
Yes, CVE-2015-5721 can allow remote attackers to execute arbitrary PHP code, potentially leading to unauthorized access.
What actions should I take if I am vulnerable to CVE-2015-5721?
If vulnerable to CVE-2015-5721, you should immediately apply the recommended updates to your Malware Information Sharing Platform software.