8.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
Description
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
Basic Information
ID
CVE-2025-66384
Source
mitre
Published
Nov 28, 2025 at 00:00
Modified
Nov 28, 2025 at 15:23
Affected Product
Vendor
MISP
Product
MISP
Affected Versions
MISP MISP 0