CVE-2025-66384

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/11/2025
Last modified:
28/11/2025

Description

app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.