OS Command Injection Vulnerability in MISP by Sirtfi
CVE-2018-6926
7.2HIGH
What is CVE-2018-6926?
An OS command injection vulnerability exists in MISP version 2.4.87, specifically within the ServersController.php file. This vulnerability allows a site administrator to override a path variable, which can lead to the injection of arbitrary OS commands on vulnerable systems, notably those running Red Hat Enterprise Linux and CentOS with rh_shell_fix enabled. Although the impact of this vulnerability is limited to site administrators, it poses significant risk as it allows for potentially malicious command execution within the operating environment.
