CVE-2022-27243: High severity Misp Misp vulnerability
Published Mar 18, 2022
·Updated
An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom terms file setting.
Affected Software
2 affected components
Misp Misp<2.4.156
Misp-project Misp<2.4.156
Remediation
Event History
Mar 18, 2022
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-27243?
The severity of CVE-2022-27243 is high with a CVSS score of 7.8.
2
What is the vulnerability in MISP before version 2.4.156?
The vulnerability in MISP before version 2.4.156 is a Local File Inclusion (LFI) vulnerability in the app/View/Users/terms.ctp file.
3
How does the vulnerability in MISP before version 2.4.156 allow Local File Inclusion?
The vulnerability in MISP before version 2.4.156 allows Local File Inclusion via the custom terms file setting in the app/View/Users/terms.ctp file.
4
What software is affected by CVE-2022-27243?
The software affected by CVE-2022-27243 is MISP versions up to (but excluding) 2.4.156.
5
How can I fix the vulnerability in MISP before version 2.4.156?
To fix the vulnerability in MISP before version 2.4.156, update to version 2.4.156 or later.