CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-48658

Critical · CVSS 9.8

MISP — Time-based SQL Injection

CVSS
9.8
nvd
EPSS
0.91%
55th pct
KEV
No
Class
oss containerizable
NVD-CWE-noinfo

Description

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.

Search profile — drives PoC discovery

Symbols AppModel.phpcheckParamlogs/indexapp/Model/AppModel.php
Keywords CVE-2023-48658MISP SQL injectionMISP logs index SQLiAppModel checkParamMISP 2.4.175 2.4.176MISP time-based SQL injection
Versions: < 2.4.176

References

Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z