First published: Fri Jun 25 2021(Updated: )
app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | =2.4.144 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-35502 is critical, with a CVSS score of 9.8.
CVE-2021-35502 affects MISP version 2.4.144.
CVE-2021-35502 allows the execution of arbitrary code or commands, which can lead to full system compromise.
Yes, a fix for CVE-2021-35502 is available in the commit 2fde6476dc3173affc61874ba2adb35400a8fda5 on the MISP GitHub repository.
You can find more information about CVE-2021-35502 at the following link: [GitHub commit](https://github.com/MISP/MISP/commit/2fde6476dc3173affc61874ba2adb35400a8fda5)