CVE-2025-66384: High severity Misp Misp vulnerability
Published Nov 28, 2025
·Updated
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmpname.
Affected Software
1 affected component
Misp Misp<2.5.24
Event History
Nov 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66384?
CVE-2025-66384 has been classified as a medium severity vulnerability due to its potential for exploitation in file upload scenarios.
2
How do I fix CVE-2025-66384?
To fix CVE-2025-66384, upgrade your MISP installation to version 2.5.24 or later.
3
What does CVE-2025-66384 affect?
CVE-2025-66384 affects MISP versions prior to 2.5.24, specifically in the EventsController.php file.
4
What kind of vulnerability is CVE-2025-66384?
CVE-2025-66384 is an input validation vulnerability related to the checking of uploaded files in MISP.
5
Is CVE-2025-66384 exploitable remotely?
Yes, CVE-2025-66384 is exploitable remotely, particularly through file upload functionalities in MISP.