{"id":"CVE-2018-6926","details":"In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.","modified":"2026-08-07T14:59:32.695087Z","published":"2018-02-12T17:29:00.323Z","references":[{"type":"FIX","url":"https://github.com/MISP/MISP/commit/0a2aa9d52492d960b9a161160acedbe9caaa4126"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/misp/misp","events":[{"introduced":"f6b9e07986e829b2a9204f272f35675dee8f41a4"},{"last_affected":"f6b9e07986e829b2a9204f272f35675dee8f41a4"},{"fixed":"0a2aa9d52492d960b9a161160acedbe9caaa4126"}],"database_specific":{"cpe":"cpe:2.3:a:misp-project:misp:2.4.87:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.4.87"},{"last_affected":"2.4.87"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2.4.87","v2.4.87"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6926.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}