Vulnerabilities > Misp > Misp > 2.4.128
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-01-26 | CVE-2020-24085 | Cross-site Scripting vulnerability in Misp 2.4.128 A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. | 4.3 |
2020-11-24 | CVE-2020-29006 | Missing Authorization vulnerability in Misp MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php. | 7.5 |
2020-11-02 | CVE-2020-28043 | Server-Side Request Forgery (SSRF) vulnerability in Misp MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL. | 5.0 |
2020-09-18 | CVE-2020-25766 | Unspecified vulnerability in Misp An issue was discovered in MISP before 2.4.132. | 5.0 |
2020-07-14 | CVE-2020-15711 | Cross-Site Request Forgery (CSRF) vulnerability in Misp In MISP before 2.4.129, setting a favourite homepage was not CSRF protected. | 6.8 |
2020-06-30 | CVE-2020-15412 | Improper Privilege Management vulnerability in Misp 2.4.128 An issue was discovered in MISP 2.4.128. | 4.0 |
2020-06-30 | CVE-2020-15411 | Improper Privilege Management vulnerability in Misp 2.4.128 An issue was discovered in MISP 2.4.128. | 7.5 |