File Upload Vulnerability in MISP Before 2.4.187
CVE-2024-29859
9.8CRITICAL
What is CVE-2024-29859?
A security flaw exists in MISP versions before 2.4.187, specifically within the add_misp_export function located in app/Controller/EventsController.php. The flaw arises from improper validation of uploaded files, which can facilitate unauthorized access or manipulation of sensitive data. Without stringent checks in place, the application becomes susceptible to potential exploitation, allowing attackers to upload malicious files that could compromise the integrity of the system or expose confidential information.
