CVE-2023-48655Critical· 9.8▾ MidnightAn issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
0.9% → 0.9%
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
misp < 2.4.176Upgrade past the affected range:
misp 2.4.176Connected by shared product, vendor, weakness, or advisory.
CVE-2023-48659Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2023-48658Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2023-48657Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2023-48656Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2026-95659Medium· 4.8MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action
CVE-2026-88921Medium· 5.1MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the con…