PT-2023-15706 · Misp · Misp
Ulaş Deniz İlhan
·
Publicado
2023-02-20
·
Atualizado
2024-02-16
·
CVE-2022-48328
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.4.167
Description
The issue arises from the mishandling of
ordered url params and additional delimiters in the app/Controller/Component/IndexFilterComponent.php file. This mishandling can lead to potential security issues.Recommendations
For versions prior to 2.4.167, update to version 2.4.167 or later to resolve the issue. As a temporary workaround, consider restricting access to the
IndexFilterComponent until a patch is applied.Exploit
Correção
Improper Handling of Exceptional Conditions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Misp