{"id":"CVE-2019-12868","details":"app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.","modified":"2026-08-07T15:00:09.682123Z","published":"2019-06-18T00:15:09.317Z","references":[{"type":"ADVISORY","url":"https://zigrin.com/advisories/misp-command-injection-via-phar-deserialization/"},{"type":"FIX","url":"https://github.com/MISP/MISP/commit/c42c5fe92783dd306b7600db1f6a25324445b40c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/misp/misp","events":[{"introduced":"add2719c99ea6f91926539894b3672087c664224"},{"last_affected":"add2719c99ea6f91926539894b3672087c664224"},{"fixed":"c42c5fe92783dd306b7600db1f6a25324445b40c"}],"database_specific":{"extracted_events":[{"introduced":"2.4.109"},{"last_affected":"2.4.109"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:misp-project:misp:2.4.109:*:*:*:*:*:*:*"}}],"versions":["2.4.109","v2.4.109","codename/tellurium"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12868.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}