Misp
by Misp
Source repositories
CVEs (145)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28884 | Med | 0.40 | 6.1 | 0.00 | Mar 27, 2023 | In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index. | ||
| CVE-2023-28607 | Med | 0.40 | 6.1 | 0.00 | Mar 18, 2023 | js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip. | ||
| CVE-2023-28606 | Med | 0.40 | 6.1 | 0.00 | Mar 18, 2023 | js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips. | ||
| CVE-2023-24070 | Med | 0.40 | 6.1 | 0.00 | Jan 23, 2023 | app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field. | ||
| CVE-2023-24027 | Med | 0.40 | 6.1 | 0.00 | Jan 20, 2023 | In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name. | ||
| CVE-2022-47928 | Med | 0.40 | 6.1 | 0.00 | Dec 22, 2022 | In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp. | ||
| CVE-2022-29533 | Med | 0.40 | 6.1 | 0.01 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page." | ||
| CVE-2022-27246 | Med | 0.40 | 6.1 | 0.01 | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default. | ||
| CVE-2021-36212 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2021 | app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view. | ||
| CVE-2020-24085 | Med | 0.40 | 6.1 | 0.01 | Jan 26, 2021 | A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code. | ||
| CVE-2021-3184 | Med | 0.40 | 6.1 | 0.01 | Jan 19, 2021 | MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button. | ||
| CVE-2021-25325 | Med | 0.40 | 6.1 | 0.01 | Jan 19, 2021 | MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs. | ||
| CVE-2021-25324 | Med | 0.40 | 6.1 | 0.01 | Jan 19, 2021 | MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp. | ||
| CVE-2020-29572 | Med | 0.40 | 6.1 | 0.01 | Dec 6, 2020 | app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field. | ||
| CVE-2020-28947 | Med | 0.40 | 6.1 | 0.01 | Nov 19, 2020 | In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled. | ||
| CVE-2020-13153 | Med | 0.40 | 6.1 | 0.01 | May 18, 2020 | app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view. | ||
| CVE-2020-10247 | Med | 0.40 | 6.1 | 0.01 | Mar 9, 2020 | MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp. | ||
| CVE-2020-10246 | Med | 0.40 | 6.1 | 0.01 | Mar 9, 2020 | MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp. | ||
| CVE-2019-14286 | Med | 0.40 | 6.1 | 0.01 | Jul 27, 2019 | In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnerability. | ||
| CVE-2019-11814 | Med | 0.40 | 6.1 | 0.01 | May 8, 2019 | An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot. |
- risk 0.40cvss 6.1epss 0.00
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
- risk 0.40cvss 6.1epss 0.00
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
- risk 0.40cvss 6.1epss 0.00
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
- risk 0.40cvss 6.1epss 0.00
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
- risk 0.40cvss 6.1epss 0.00
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
- risk 0.40cvss 6.1epss 0.00
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.
- risk 0.40cvss 6.1epss 0.01
app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
- risk 0.40cvss 6.1epss 0.01
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
- risk 0.40cvss 6.1epss 0.01
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
- risk 0.40cvss 6.1epss 0.01
app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
- risk 0.40cvss 6.1epss 0.01
In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot.
Page 4 of 8