vendor:
MISP
by:
Tm9jdGlz
8.8
CVSS
HIGH
Command Injection
89
CWE
Product Name: MISP
Affected Version From: 2.4.90
Affected Version To: 2.4.99
Patch Exists: YES
Related CWE: CVE-2018-19908
CPE: a:misp:misp
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: 2.4.97
2019
SQL command execution via command injection in STIX module
A vulnerability in the STIX module of MISP (Malware Information Sharing Platform) allows an attacker to execute arbitrary SQL commands via command injection. This exploit uses a payload as a stix filename, which is then encoded and passed to the vulnerable application. The payload contains a set of commands that are used to extract the database credentials from the database.php file, and then use them to execute the arbitrary SQL command. The exploit also uses python to decode the payload and then execute it.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of MISP.