# MISP patches two authenticated SQLi flaws

Published: 2023-02-20 · Severity: high · Sectors: government-national, technology
Canonical: https://vorant.io/reports/7e3306b3-7e26-5a45-8f3e-64e6f66c8159/misp-patches-two-authenticated-sqli-flaws

> MISP fixed two SQL injection vulnerabilities allowing any authenticated user to run arbitrary SQL queries, patched in v2.4.166 and v2.4.167.

MISP disclosed two separate SQL injection vulnerabilities discovered by independent researchers over a two-month period, both allowing an authenticated user to execute arbitrary SQL queries against the platform's database. The first, reported by Jakub Onderka, stemmed from unsafe handling of the CakePHP find() function's order parameter used for custom field sorting on endpoints like RestSearch. The second, reported by Dawid Czarnecki of Zigrin Security on behalf of the Luxembourgish army, involved the CRUD component's search parameter field names not being properly sanitized despite lookup values being safe.

The MISP project opted for a silent fix approach, disguising the patches as refactors or minor bug fixes and bundling in unrelated security work to downplay the criticality publicly while giving the community time to upgrade before disclosure. The order-parameter flaw was fixed in v2.4.166 (CVE-2022-48329) and the CRUD search-parameter flaw was fixed in v2.4.167 (CVE-2022-48328), both through field allow-listing. No evidence of active exploitation was reported; this is a responsible disclosure and patch notice affecting a widely used threat intelligence sharing platform.

## Mentioned in this report

- Vulnerabilities: CVE-2022-48328, CVE-2022-48329

Source reporting: https://www.misp-project.org/2023/02/20/critical_sql_injection_vulnerabilities_fixed.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7e3306b3-7e26-5a45-8f3e-64e6f66c8159/misp-patches-two-authenticated-sqli-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
