Vulnerabilities > Misp

DATE CVE VULNERABILITY TITLE RISK
2021-07-30 CVE-2021-37742 Cross-Site Scripting vulnerability in Misp 2.4.147
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
network
misp CWE-79
3.5
2021-07-30 CVE-2021-37743 Cross-Site Scripting vulnerability in Misp 2.4.147
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
network
misp CWE-79
3.5
2021-07-07 CVE-2021-36212 Cross-Site Scripting vulnerability in Misp
app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
network
misp CWE-79
4.3
2021-06-25 CVE-2021-35502 Unspecified vulnerability in Misp 2.4.144
app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.
network
low complexity
misp
7.5
2021-04-23 CVE-2021-31780 Improper Cross-Boundary Removal of Sensitive Data vulnerability in Misp 2.4.141
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit.
network
low complexity
misp CWE-212
5.0
2021-03-02 CVE-2021-27904 Unspecified vulnerability in Misp
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139.
local
low complexity
misp
2.1
2021-01-26 CVE-2020-24085 Cross-Site Scripting vulnerability in Misp 2.4.128
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function.
network
misp CWE-79
4.3
2021-01-19 CVE-2021-3184 Cross-Site Scripting vulnerability in Misp 2.4.136
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
network
misp CWE-79
4.3
2021-01-19 CVE-2021-25325 Cross-Site Scripting vulnerability in Misp 2.4.136
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp.
network
misp CWE-79
4.3
2021-01-19 CVE-2021-25324 Cross-Site Scripting vulnerability in Misp 2.4.136
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
network
misp CWE-79
4.3