PT-2026-48996 · Misp · Misp
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Green |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
A path traversal issue exists in the
getOrgLogo() function of the OrganisationsController. The software constructs file paths for organization logos using fields controlled by the organization, such as id, name, and uuid, without verifying that the resulting path stays within the intended APP/files/img/orgs/ directory. An attacker who can modify an organization field, such as the organization name, can use path traversal sequences to retrieve arbitrary readable .png or .svg files from locations outside the designated logo directory.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp