CVE Vulnerabilities

CVE-2025-66384

Incorrect Provision of Specified Functionality

Published: Nov 28, 2025 | Modified: Nov 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Potential Mitigations

References