First published: Fri Nov 17 2023(Updated: )
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp-project Malware Information Sharing Platform | <2.4.176 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-48655 is critical with a rating of 9.8.
CVE-2023-48655 affects MISP versions up to and including 2.4.176.
CVE-2023-48655 addresses an issue in the app/Controller/Component/IndexFilterComponent.php file of MISP where query parameters are not properly filtered out.
To fix CVE-2023-48655, it is recommended to update MISP to version 2.4.177 or later.
You can find more information about CVE-2023-48655 on the following GitHub links: [link1](https://github.com/MISP/MISP/compare/v2.4.175...v2.4.176) and [link2](https://github.com/MISP/MISP/commit/158c8b2f788b75e0d26e9249a75e1be291e59d4b).