{"id":"CVE-2015-5719","title":"app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.","summary":"app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"misp-project","product":"misp","affected":["misp <= 2.3.91"],"published":"2016-09-03","updated":"2026-06-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2015-5719","references":[{"url":"http://www.securityfocus.com/bid/92740","label":"cve@mitre.org"},{"url":"https://github.com/MISP/MISP/commit/27cc167c3355ec76292235d7f5f4e0016bfd7699","label":"cve@mitre.org"},{"url":"https://www.circl.lu/advisory/CVE-2015-5719/","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/92740","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/MISP/MISP/commit/27cc167c3355ec76292235d7f5f4e0016bfd7699","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.circl.lu/advisory/CVE-2015-5719/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02045,"epssPercentile":0.80074,"ingestedAt":"2026-06-29T13:24:33.158Z","slug":"CVE-2015-5719","body":"## Overview\n\napp/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.\n\n## Affected\n\n- `misp <= 2.3.91`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}