PT-2026-96771 · Misp · Misp

·

CVE-2026-95703

·

Publicado

2026-09-22

·

Atualizado

2026-09-22

CVSS v4.0

5.1

Média

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In MISP, the OrganisationsController:: uploadLogo method processed a caller-supplied tmp name value with filesystem probes (file exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP file upload via is uploaded file. An authenticated site-admin user could supply an arbitrary server file path as the tmp name parameter. The application would then probe that path and return distinct validation error messages depending on whether the file existed and what its image type was, effectively creating a file-existence and image-type oracle against the server filesystem.
The vulnerability requires site-admin privileges and does not allow arbitrary file read, code execution, or modification; the impact is limited to disclosure of whether a given path exists on the server and, for image files, their type.

Correção

RCE

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-95703

Produtos afetados

Misp