Invalid File Upload Logic in MISP Platform Affecting Security
CVE-2025-66384
8.2HIGH
What is CVE-2025-66384?
MISP versions prior to 2.5.24 exhibit a flaw in the logic used to validate uploaded files. Specifically, the logic fails to properly check the 'tmp_name' of uploaded files, potentially allowing attackers to exploit this weakness to upload malicious files. This vulnerability underscores the importance of robust file validation mechanisms to safeguard web applications from potential security threats.
Affected Version(s)
MISP 0 < 2.5.24
