First published: Mon Feb 20 2023(Updated: )
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.167 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-48328 is critical with a score of 9.8.
The affected software of CVE-2022-48328 is MISP before version 2.4.167.
CVE-2022-48328 affects MISP by mishandling ordered_url_params and additional_delimiters in the app/Controller/Component/IndexFilterComponent.php file.
Yes, fixes and patches for CVE-2022-48328 are available in the following commits: [Commit 1](https://github.com/MISP/MISP/commit/1edbc2569989f844799261a5f90edfa433d7dbcc) and [Commit 2](https://github.com/MISP/MISP/commit/206f540f0275af2dd2a86275abc199df41e72a21).
The Common Weakness Enumeration (CWE) ID for CVE-2022-48328 is CWE-755.