VORANT. Threat Intelligence Sign in Get the full feed

MISP patches two authenticated SQLi flaws

high vulnerability government-nationaltechnology

MISP fixed two SQL injection vulnerabilities allowing any authenticated user to run arbitrary SQL queries, patched in v2.4.166 and v2.4.167.

MISP disclosed two separate SQL injection vulnerabilities discovered by independent researchers over a two-month period, both allowing an authenticated user to execute arbitrary SQL queries against the platform's database. The first, reported by Jakub Onderka, stemmed from unsafe handling of the CakePHP find() function's order parameter used for custom field sorting on endpoints like RestSearch. The second, reported by Dawid Czarnecki of Zigrin Security on behalf of the Luxembourgish army, involved the CRUD component's search parameter field names not being properly sanitized despite lookup values being safe.

The MISP project opted for a silent fix approach, disguising the patches as refactors or minor bug fixes and bundling in unrelated security work to downplay the criticality publicly while giving the community time to upgrade before disclosure. The order-parameter flaw was fixed in v2.4.166 (CVE-2022-48329) and the CRUD search-parameter flaw was fixed in v2.4.167 (CVE-2022-48328), both through field allow-listing. No evidence of active exploitation was reported; this is a responsible disclosure and patch notice affecting a widely used threat intelligence sharing platform.

Mentioned in this report

Vulnerabilities CVE-2022-48328CVE-2022-48329

Source reporting: https://www.misp-project.org/2023/02/20/critical_sql_injection_vulnerabilities_fixed.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free