CVE-2021-39302

MISP/MISP
on github

Published

Severity

CVSS v3:
9.8 CRITICAL
CVSS v2:
6.8 MEDIUM

Description

MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:misp:misp:2.4.148:*:*:*:*:*:*:*n/an/a2.4.148

External Links