Vulnerabilities > Misp > Misp > 2.4.136

DATE CVE VULNERABILITY TITLE RISK
2021-01-19 CVE-2021-3184 Cross-site Scripting vulnerability in Misp 2.4.136
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
network
misp CWE-79
4.3
2021-01-19 CVE-2021-25325 Cross-site Scripting vulnerability in Misp 2.4.136
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp.
network
misp CWE-79
4.3
2021-01-19 CVE-2021-25324 Cross-site Scripting vulnerability in Misp 2.4.136
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
network
misp CWE-79
4.3
2021-01-19 CVE-2021-25323 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Misp 2.4.136
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
network
low complexity
misp CWE-640
6.4