CVE-2015-5721
Critical · CVSS 9.8Malware Information Sharing Platform (MISP) — PHP object injection via crafted serialized data
- CVSS
- 9.8
- nvd
- EPSS
- 2.61%
- 83th pct
- KEV
- No
- Class
- other
- CWE-94
Description
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.
Search profile — drives PoC discovery
Symbols TemplatesController.phppopulate_event_from_template_attributes.ctpunserializePHP object injection
Keywords CVE-2015-5721MISP PHP object injectionMISP serialized data exploitTemplatesController object injectionpopulate_event_from_template_attributesMISP before 2.3.90 PoCMISP deserialization vulnerability
Versions: < 2.3.90
References
- http://www.securityfocus.com/bid/92739
- https://github.com/MISP/MISP/commit/415d85102d5aa5f96f4f11a17c86b59bb9cc0d56
- https://www.circl.lu/advisory/CVE-2015-5721/
- http://www.securityfocus.com/bid/92739
- https://github.com/MISP/MISP/commit/415d85102d5aa5f96f4f11a17c86b59bb9cc0d56
- https://www.circl.lu/advisory/CVE-2015-5721/
Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z