Vulnerabilities > Misp > Misp > 2.4.134

DATE CVE VULNERABILITY TITLE RISK
2020-11-24 CVE-2020-29006 Missing Authorization vulnerability in Misp
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
network
low complexity
misp CWE-862
7.5
2020-11-19 CVE-2020-28947 Cross-site Scripting vulnerability in Misp 2.4.134
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
network
misp CWE-79
4.3