CVE-2025-66386

Publication date

2025-11-28 00:00:00

Family

mitre

State

PUBLISHED

Description

app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.