In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP file upload via is_upload
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-95806 | 7.7 HIGH | MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influe |
| CVE-2026-95658 | 6.9 MEDIUM | MISP CSRF vulnerability in workflow moduleStatelessExecution allows cross-site execution o |
| CVE-2026-95754 | 6.9 MEDIUM | MISP: Disabled-user check ineffective in pre-authentication TOTP login branch |
| CVE-2026-95679 | 6.9 MEDIUM | MISP Unauthenticated Blind SSRF via XML Body Processing |
| CVE-2026-95667 | 6.9 MEDIUM | MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Credentials |
| CVE-2026-95697 | 5.3 MEDIUM | MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Me |
| CVE-2026-95805 | 5.3 MEDIUM | MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restric |
| CVE-2026-95698 | 5.3 MEDIUM | MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name |
| CVE-2026-95671 | 5.3 MEDIUM | MISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collecti |
| CVE-2026-95693 | 5.3 MEDIUM | MISP Information Disclosure via Forged Upload Path |
| CVE-2026-95674 | 5.3 MEDIUM | MISP EventsController queryEnrichment allows querying unavailable or legacy modules withou |
| CVE-2026-95683 | 5.3 MEDIUM | MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL |
| CVE-2026-95685 | 5.3 MEDIUM | MISP Missing Authorization on replaceSuggestionInReport Event Report Action |
| CVE-2026-95661 | 5.1 MEDIUM | MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type |
| CVE-2026-95665 | 5.1 MEDIUM | MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSON |
| CVE-2026-95701 | 5.1 MEDIUM | MISP Path Traversal via Organization Name in Org-Statistics Logo Check |
| CVE-2026-95659 | 4.8 MEDIUM | MISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind Thread |
| CVE-2026-95682 | 4.8 MEDIUM | MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View |
No comments yet