{"id":"CVE-2021-39302","details":"MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.","modified":"2026-08-07T19:46:53.798093Z","published":"2021-08-19T17:15:07.313Z","references":[{"type":"FIX","url":"https://github.com/MISP/MISP/commit/20d9020b76d1f6790c4d84e020d0cc97c929f66b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/misp/misp","events":[{"introduced":"96b4f86c62fa66b10dd46dc3532aa873c27f1878"},{"last_affected":"96b4f86c62fa66b10dd46dc3532aa873c27f1878"},{"fixed":"20d9020b76d1f6790c4d84e020d0cc97c929f66b"}],"database_specific":{"cpe":"cpe:2.3:a:misp-project:misp:2.4.148:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.4.148"},{"last_affected":"2.4.148"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2.4.148","v2.4.148"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-39302.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}