SQL Injection Vulnerability in MISP Product by MISP
CVE-2021-39302
9.8CRITICAL
What is CVE-2021-39302?
The MISP 2.4.148 version has a vulnerability that allows SQL injection due to improper handling of the $conditions['org'] value in the app/Model/Log.php file. This could potentially enable an attacker to manipulate the database and access sensitive information, posing significant risks to data integrity and confidentiality in specific configurations.
