First published: Fri Mar 18 2022(Updated: )
An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom terms file setting.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.156 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-27243 is high with a CVSS score of 7.8.
The vulnerability in MISP before version 2.4.156 is a Local File Inclusion (LFI) vulnerability in the app/View/Users/terms.ctp file.
The vulnerability in MISP before version 2.4.156 allows Local File Inclusion via the custom terms file setting in the app/View/Users/terms.ctp file.
The software affected by CVE-2022-27243 is MISP versions up to (but excluding) 2.4.156.
To fix the vulnerability in MISP before version 2.4.156, update to version 2.4.156 or later.