VulnSea

misp vulnerabilities

CVEs whose affected-version data names the misp package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

146 CVEsRSS

CVE-2024-29859Critical· 9.8
2y ago

In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

Midnightmisp-project · mispEPSS 0.82%via NVD
CVE-2024-29858Critical· 9.8
2y ago

In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.

In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.

Midnightmisp-project · mispEPSS 0.38%via NVD
CVE-2024-25675Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.184

An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.

Midnightmisp-project · mispEPSS 0.82%via NVD
CVE-2024-25674Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.184

An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.

Midnightmisp-project · mispEPSS 0.78%via NVD
CVE-2023-50918Critical· 9.8
2y ago

app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

Midnightmisp-project · mispEPSS 0.79%via NVD
CVE-2023-49926Medium· 6.1
2y ago

app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2023-48659Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.

Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48658Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.

Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48657Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.

Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48656Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.

Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48655Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.

Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-41098Medium· 6.1
3y ago

An issue was discovered in MISP 2.4.174

An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.

Sunlitmisp-project · mispEPSS 0.42%via NVD
CVE-2023-40224Medium· 6.1
3y ago

MISP 2.4.174 allows XSS in app/View/Events/index.ctp.

MISP 2.4.174 allows XSS in app/View/Events/index.ctp.

Sunlitmisp-project · mispEPSS 0.43%via NVD
CVE-2023-37307Medium· 5.4
3y ago

In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

Sunlitmisp-project · mispEPSS 0.50%via NVD
CVE-2023-37306High· 7.5
3y ago

MISP 2.4.172 mishandles different certificate file extensions in server sync

MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

Twilightmisp-project · mispEPSS 0.53%via NVD
CVE-2023-28884Medium· 6.1
3y ago

In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.

In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.

Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2023-28607Medium· 6.1
3y ago

js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.

js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.

Sunlitmisp-project · mispEPSS 0.38%via NVD
CVE-2023-28606Medium· 6.1
3y ago

js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.

js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.

Sunlitmisp-project · mispEPSS 0.38%via NVD
CVE-2022-48329Critical· 9.8
3y ago

MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.

MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.

Midnightmisp-project · mispEPSS 0.94%via NVD
CVE-2022-48328Critical· 9.8
3y ago

app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

Midnightmisp-project · mispEPSS 1.3%via NVD
CVE-2023-24070Medium· 6.1
3y ago

app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.

app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.

Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2023-24027Medium· 6.1
3y ago

In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.

In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.

Sunlitmisp-project · mispEPSS 0.40%via NVD
CVE-2022-47928Medium· 6.1
3y ago

In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.

In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.

Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2022-42724Medium· 4.3
3y ago

app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

Sunlitmisp-project · mispEPSS 0.49%via NVD
CVE-2022-29534High· 7.5
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

Twilightmisp-project · mispEPSS 1.6%via NVD
CVE-2022-29533Medium· 6.1
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."

Sunlitmisp-project · mispEPSS 0.84%via NVD
CVE-2022-29532Medium· 4.8
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.

Sunlitmisp-project · mispEPSS 0.84%via NVD
CVE-2022-29531Medium· 5.4
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.

Sunlitmisp-project · mispEPSS 0.83%via NVD
CVE-2022-29530Medium· 5.4
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.

Sunlitmisp-project · mispEPSS 0.83%via NVD
CVE-2022-29529Medium· 5.4
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.

Sunlitmisp-project · mispEPSS 0.83%via NVD
misp vulnerabilities (CVEs) — page 3 · VulnSea