CVE-2018-19908: Misp-Project Misp
High severity, CVSS 8.8. EPSS: 17.3% chance of exploitation in the next 30 days.
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.
Affected products
- Misp-Project Misp: from 2.4.90, before 2.4.99 (fixed in 2.4.99)
Published 2018-12-06. Last modified 2026-06-22.