CVE-2015-5719
Critical · CVSS 9.8Malware Information Sharing Platform (MISP) — Improper filename restriction / path traversal
- CVSS
- 9.8
- nvd
- EPSS
- 2.27%
- 81th pct
- KEV
- No
- Class
- other
- NVD-CWE-noinfo
Description
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.
Search profile — drives PoC discovery
Symbols TemplatesController.phptmp/files/app/Controller/TemplatesController.php
Keywords CVE-2015-5719MISP TemplatesControllerMISP tmp/files filename restrictionMISP 2.3.92MISP template file upload vulnerability
Versions: before 2.3.92
References
- http://www.securityfocus.com/bid/92740
- https://github.com/MISP/MISP/commit/27cc167c3355ec76292235d7f5f4e0016bfd7699
- https://www.circl.lu/advisory/CVE-2015-5719/
- http://www.securityfocus.com/bid/92740
- https://github.com/MISP/MISP/commit/27cc167c3355ec76292235d7f5f4e0016bfd7699
- https://www.circl.lu/advisory/CVE-2015-5719/
Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z