VulnSea

misp vulnerabilities

CVEs whose affected-version data names the misp package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

162 CVEsRSS

CVE-2019-11812Medium· 6.1
7y ago

A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107

A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link.

Sunlitmisp-project · mispEPSS 0.81%via NVD
CVE-2019-10254Medium· 6.1
7y ago

In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.

In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.

Sunlitmisp-project · mispEPSS 0.88%via NVD
CVE-2019-9482Medium· 5.3
7y ago

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (…

Sunlitmisp-project · mispEPSS 0.75%via NVD
CVE-2018-19908High· 8.8PoC
7y ago

An issue was discovered in MISP 2.4.9x before 2.4.99

An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user …

Midnightmisp-project · mispEPSS 17%via NVD
CVE-2018-12649Critical· 9.8
8y ago

An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92

An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only…

Midnightmisp-project · mispEPSS 1.5%via NVD
CVE-2018-11562Medium· 6.1
8y ago

An issue was discovered in MISP 2.4.91

An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.

Sunlitmisp-project · mispEPSS 0.81%via NVD
CVE-2018-6926High· 7.2
8y ago

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site adm…

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site adm…

Twilightmisp-project · mispEPSS 1.7%via NVD
CVE-2017-16946Medium· 4.9
8y ago

The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.

The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.

Sunlitmisp-project · mispEPSS 1.1%via NVD
CVE-2017-13671Medium· 6.1
9y ago

app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments

app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.

Sunlitmisp-project · mispEPSS 0.97%via NVD
CVE-2015-5721Critical· 9.8
10y ago

Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.

Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.

Midnightmisp-project · mispEPSS 2.6%via NVD
CVE-2015-5720Medium· 6.1
10y ago

Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add…

Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add…

Sunlitmisp-project · mispEPSS 1.4%via NVD
CVE-2015-5719Critical· 9.8
10y ago

app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.

app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.

Midnightmisp-project · mispEPSS 2.3%via NVD
misp vulnerabilities (CVEs) — page 6 · VulnSea