Impact
The MISP blocklist workflow module accepts a user-supplied blocklist filename without checking the extension, allowing an attacker with site‑administrator rights to upload files with arbitrary extensions into the export directory. If the web server interprets files in that directory as scripts, the attacker can execute arbitrary code with the privileges of the web server process, leading to full compromise of the MISP installation’s confidentiality, integrity, and availability.
Affected Systems
Vulnerable MISP installations running any version prior to 2.5.47 are affected. The flaw exists in the blocklist workflow module within MISP itself; no external product is required.
Risk and Exploitability
The vulnerability has a CVSS score of 8.6, indicating high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. The attack vector requires site‑administrator privileges within MISP and does not need additional user interaction beyond triggering the workflow action with a crafted filename. Once exploited, the attacker gains the same privileges as the web server, effectively executing arbitrary code on the server.
OpenCVE Enrichment