Critical SQL injection vulnerabilities in MISP (fixed in v2.4.166 and v2.4.167)
Critical SQL injection vulnerabilities in MISP (fixed in v2.4.166 and v2.4.167)
Introduction
As of the past 2 months, we’ve received two separate reports of two unrelated SQLi vector vulnerabilities in MISP that can lead to any authenticated user being able to execute arbitrary SQL queries in MISP.