CVE-2018-6926

HIGH

Misp - OS Command Injection

Title source: rule
STIX 2.1

Description

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0053
EPSS Percentile 67.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
misp/misp 2.4.87
Published Feb 12, 2018
Tracked Since Feb 18, 2026