Vulnerabilities > Misp > Misp > 2.4.128

DATE CVE VULNERABILITY TITLE RISK
2021-01-26 CVE-2020-24085 Cross-site Scripting vulnerability in Misp 2.4.128
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function.
network
misp CWE-79
4.3
2020-11-24 CVE-2020-29006 Missing Authorization vulnerability in Misp
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
network
low complexity
misp CWE-862
7.5
2020-11-02 CVE-2020-28043 Server-Side Request Forgery (SSRF) vulnerability in Misp
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
network
low complexity
misp CWE-918
5.0
2020-09-18 CVE-2020-25766 Unspecified vulnerability in Misp
An issue was discovered in MISP before 2.4.132.
network
low complexity
misp
5.0
2020-07-14 CVE-2020-15711 Cross-Site Request Forgery (CSRF) vulnerability in Misp
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
network
misp CWE-352
6.8
2020-06-30 CVE-2020-15412 Improper Privilege Management vulnerability in Misp 2.4.128
An issue was discovered in MISP 2.4.128.
network
low complexity
misp CWE-269
4.0
2020-06-30 CVE-2020-15411 Improper Privilege Management vulnerability in Misp 2.4.128
An issue was discovered in MISP 2.4.128.
network
low complexity
misp CWE-269
7.5