HIGH

CVE-2018-19908

CVSS v3

8.8

HIGH

EPSS Score

43.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.

Technical details

Published
12/6/2018

Frequently asked questions

What is CVE-2018-19908?

An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.

Is CVE-2018-19908 actively exploited?

Active exploitation of CVE-2018-19908 has not been confirmed. The EPSS score is 43.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-19908?

CVE-2018-19908 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2018-19908 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.