Path Traversal Vulnerability in MISP Software by MISP Project
CVE-2025-66386
4.1MEDIUM
What is CVE-2025-66386?
The MISP software, specifically in app/Model/EventReport.php before version 2.5.27, is vulnerable to a path traversal issue. This vulnerability allows site administrators to leverage the flaw to access unauthorized files, raising significant security concerns for data integrity and access control within the system.
Affected Version(s)
MISP 0 < 2.5.27
