Vendor CVEs
Misp
All CVEs
242 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-13153 | Med | 0.40 | 6.1 | 0.01 | May 18, 2020 | app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view. | ||
| CVE-2020-10247 | Med | 0.40 | 6.1 | 0.01 | Mar 9, 2020 | MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp. | ||
| CVE-2020-10246 | Med | 0.40 | 6.1 | 0.01 | Mar 9, 2020 | MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp. | ||
| CVE-2019-14286 | Med | 0.40 | 6.1 | 0.01 | Jul 27, 2019 | In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnerability. | ||
| CVE-2019-11814 | Med | 0.40 | 6.1 | 0.01 | May 8, 2019 | An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot. | ||
| CVE-2019-11813 | Med | 0.40 | 6.1 | 0.01 | May 8, 2019 | An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes with javascript:// links. | ||
| CVE-2019-11812 | Med | 0.40 | 6.1 | 0.01 | May 8, 2019 | A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link. | ||
| CVE-2019-10254 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2019 | In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability. | ||
| CVE-2018-11562 | Med | 0.40 | 6.1 | 0.01 | May 30, 2018 | An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter. | ||
| CVE-2017-15216 | Med | 0.40 | 6.1 | 0.01 | Oct 10, 2017 | MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js. | ||
| CVE-2017-13671 | Med | 0.40 | 6.1 | 0.01 | Aug 24, 2017 | app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation. | ||
| CVE-2017-7215 | Med | 0.40 | 6.1 | 0.02 | Mar 21, 2017 | Cross site scripting in some view elements in the index filter tool in app/webroot/js/misp2.4.68.js and the organisation landing page in app/View/Organisations/ajax/landingpage.ctp of MISP before 2.4.69 allows remote attackers to inject arbitrary web script or HTML. | ||
| CVE-2026-94404 | Hig | 0.39 | — | — | Sep 21, 2026 | MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protection against forged requests. Because… | ||
| CVE-2026-91846 | Hig | 0.39 | — | 0.00 | Sep 15, 2026 | Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselves only store UUIDs, while the collection… | ||
| CVE-2026-91825 | Hig | 0.39 | — | 0.00 | Sep 15, 2026 | Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted… | ||
| CVE-2026-88915 | Hig | 0.39 | — | 0.00 | Sep 10, 2026 | Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value into event creation without… | ||
| CVE-2026-86283 | Hig | 0.39 | — | 0.00 | Sep 6, 2026 | MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs… | ||
| CVE-2026-54359 | Hig | 0.39 | — | 0.00 | Jun 12, 2026 | MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or AJAX requests are not restricted based on the browser-provided Sec-Fetch-Site… | ||
| CVE-2026-95754 | Med | 0.38 | — | — | Sep 22, 2026 | In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.totp, and… | ||
| CVE-2026-95679 | Med | 0.38 | — | — | Sep 22, 2026 | MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in its readFile guard condition (readFile && http || https), where PHP operator precedence causes the https branch to bypass… | ||
| CVE-2026-95667 | Med | 0.38 | — | — | Sep 22, 2026 | The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /var/log/misp_install.log.pipe to capture all installer output. The log captures highly sensitive data including the… | ||
| CVE-2026-95658 | Med | 0.38 | — | — | Sep 22, 2026 | MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because… | ||
| CVE-2026-94379 | Med | 0.38 | — | — | Sep 21, 2026 | The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PUT) before enforcing bruteforce protection,… | ||
| CVE-2026-92003 | Med | 0.38 | — | 0.00 | Sep 15, 2026 | Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: - API requests with no authentication key; - requests supplying an API key with an… | ||
| CVE-2026-91819 | Med | 0.38 | — | 0.00 | Sep 15, 2026 | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the… | ||
| CVE-2026-77710 | Med | 0.38 | — | 0.00 | Aug 21, 2026 | A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the… | ||
| CVE-2026-72759 | Med | 0.38 | — | 0.00 | Aug 10, 2026 | In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record references a deleted conversion, the associated conversion lookup returns None. The previous logic only denied access when the… | ||
| CVE-2026-53693 | Med | 0.38 | — | 0.00 | Jun 10, 2026 | A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline JavaScript event… | ||
| CVE-2020-8891 | Med | 0.38 | 5.9 | 0.01 | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests. | ||
| CVE-2020-8890 | Med | 0.38 | 5.9 | 0.01 | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests. | ||
| CVE-2026-85238 | Med | 0.37 | 6.8 | 0.00 | Sep 3, 2026 | MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session… | ||
| CVE-2024-58129 | Med | 0.36 | 5.5 | 0.00 | Mar 28, 2025 | In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page. | ||
| CVE-2024-58128 | Med | 0.36 | 5.5 | 0.00 | Mar 28, 2025 | In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link. | ||
| CVE-2021-27904 | Med | 0.36 | 5.5 | 0.00 | Mar 2, 2021 | An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors. | ||
| CVE-2026-94393 | Med | 0.35 | — | — | Sep 21, 2026 | When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report… | ||
| CVE-2026-86408 | Med | 0.35 | 6.5 | 0.00 | Sep 7, 2026 | Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields such as: * type… | ||
| CVE-2026-86347 | Med | 0.35 | 6.5 | 0.00 | Sep 7, 2026 | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-management operations. The upload… | ||
| CVE-2026-85239 | Med | 0.35 | 6.5 | 0.00 | Sep 3, 2026 | A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the… | ||
| CVE-2026-10860 | Med | 0.35 | 6.5 | 0.00 | Jun 4, 2026 | A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === null && POST) || DELETE,… | ||
| CVE-2026-9136 | Med | 0.35 | 6.5 | 0.00 | May 20, 2026 | A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a supplied primary key as an… | ||
| CVE-2025-67906 | Med | 0.35 | 5.4 | 0.00 | Dec 15, 2025 | In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. | ||
| CVE-2023-37307 | Med | 0.35 | 5.4 | 0.01 | Jun 30, 2023 | In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts. | ||
| CVE-2022-29531 | Med | 0.35 | 5.4 | 0.01 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name. | ||
| CVE-2022-29530 | Med | 0.35 | 5.4 | 0.01 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters. | ||
| CVE-2022-29529 | Med | 0.35 | 5.4 | 0.01 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field. | ||
| CVE-2021-37743 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2021 | app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format. | ||
| CVE-2021-37742 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2021 | app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships. | ||
| CVE-2021-37534 | Med | 0.35 | 5.4 | 0.01 | Jul 26, 2021 | app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster. | ||
| CVE-2019-19379 | Med | 0.35 | 5.3 | 0.01 | Nov 28, 2019 | In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data. | ||
| CVE-2019-16202 | Med | 0.35 | 6.5 | 0.01 | Sep 10, 2019 | MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP… |
- risk 0.40cvss 6.1epss 0.01
app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
- risk 0.40cvss 6.1epss 0.01
In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes with javascript:// links.
- risk 0.40cvss 6.1epss 0.01
A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link.
- risk 0.40cvss 6.1epss 0.01
In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.
- risk 0.40cvss 6.1epss 0.01
MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.
- risk 0.40cvss 6.1epss 0.01
app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.
- risk 0.40cvss 6.1epss 0.02
Cross site scripting in some view elements in the index filter tool in app/webroot/js/misp2.4.68.js and the organisation landing page in app/View/Organisations/ajax/landingpage.ctp of MISP before 2.4.69 allows remote attackers to inject arbitrary web script or HTML.
- risk 0.39cvss —epss —
MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protection against forged requests. Because…
- risk 0.39cvss —epss 0.00
Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselves only store UUIDs, while the collection…
- risk 0.39cvss —epss 0.00
Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted…
- risk 0.39cvss —epss 0.00
Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value into event creation without…
- risk 0.39cvss —epss 0.00
MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs…
- risk 0.39cvss —epss 0.00
MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or AJAX requests are not restricted based on the browser-provided Sec-Fetch-Site…
- risk 0.38cvss —epss —
In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.totp, and…
- risk 0.38cvss —epss —
MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in its readFile guard condition (readFile && http || https), where PHP operator precedence causes the https branch to bypass…
- risk 0.38cvss —epss —
The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /var/log/misp_install.log.pipe to capture all installer output. The log captures highly sensitive data including the…
- risk 0.38cvss —epss —
MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because…
- risk 0.38cvss —epss —
The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PUT) before enforcing bruteforce protection,…
- risk 0.38cvss —epss 0.00
Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: - API requests with no authentication key; - requests supplying an API key with an…
- risk 0.38cvss —epss 0.00
Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the…
- risk 0.38cvss —epss 0.00
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the…
- risk 0.38cvss —epss 0.00
In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record references a deleted conversion, the associated conversion lookup returns None. The previous logic only denied access when the…
- risk 0.38cvss —epss 0.00
A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline JavaScript event…
- risk 0.38cvss 5.9epss 0.01
An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.
- risk 0.38cvss 5.9epss 0.01
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.
- risk 0.37cvss 6.8epss 0.00
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session…
- risk 0.36cvss 5.5epss 0.00
In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.
- risk 0.36cvss 5.5epss 0.00
In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.
- risk 0.35cvss —epss —
When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report…
- risk 0.35cvss 6.5epss 0.00
Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields such as: * type…
- risk 0.35cvss 6.5epss 0.00
Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-management operations. The upload…
- risk 0.35cvss 6.5epss 0.00
A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the…
- risk 0.35cvss 6.5epss 0.00
A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === null && POST) || DELETE,…
- risk 0.35cvss 6.5epss 0.00
A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a supplied primary key as an…
- risk 0.35cvss 5.4epss 0.00
In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
- risk 0.35cvss 5.4epss 0.01
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
- risk 0.35cvss 5.4epss 0.01
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
- risk 0.35cvss 5.4epss 0.01
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
- risk 0.35cvss 5.4epss 0.01
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
- risk 0.35cvss 5.3epss 0.01
In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.
- risk 0.35cvss 6.5epss 0.01
MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP…
Page 3 of 5