CVE-2025-66384
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/11/2025
Last modified:
28/11/2025
Description
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
Impact
Base Score 3.x
8.20
Severity 3.x
HIGH



