CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2015-5721

Critical · CVSS 9.8

Malware Information Sharing Platform (MISP) — PHP object injection via crafted serialized data

CVSS
9.8
nvd
EPSS
2.61%
83th pct
KEV
No
Class
other
CWE-94

Description

Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.

Search profile — drives PoC discovery

Symbols TemplatesController.phppopulate_event_from_template_attributes.ctpunserializePHP object injection
Keywords CVE-2015-5721MISP PHP object injectionMISP serialized data exploitTemplatesController object injectionpopulate_event_from_template_attributesMISP before 2.3.90 PoCMISP deserialization vulnerability
Versions: < 2.3.90

References

Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z