app/Controller/EventsController.php in MISP before 2.5.24...
High severity
Unreviewed
Published
Nov 28, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Nov 28, 2025
Published to the GitHub Advisory Database
Nov 28, 2025
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
References