Vulnerabilities > Misp

DATE CVE VULNERABILITY TITLE RISK
2021-03-02 CVE-2021-27904 Unspecified vulnerability in Misp
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139.
local
low complexity
misp
5.5
2021-01-26 CVE-2020-24085 Cross-site Scripting vulnerability in Misp 2.4.128
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function.
network
low complexity
misp CWE-79
6.1
2021-01-19 CVE-2021-3184 Cross-site Scripting vulnerability in Misp 2.4.136
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
network
low complexity
misp CWE-79
6.1
2021-01-19 CVE-2021-25325 Cross-site Scripting vulnerability in Misp 2.4.136
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp.
network
low complexity
misp CWE-79
6.1
2021-01-19 CVE-2021-25324 Cross-site Scripting vulnerability in Misp 2.4.136
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
network
low complexity
misp CWE-79
6.1
2021-01-19 CVE-2021-25323 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Misp 2.4.136
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
network
low complexity
misp CWE-640
critical
9.1
2020-12-06 CVE-2020-29572 Cross-site Scripting vulnerability in Misp 2.4.135
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
network
low complexity
misp CWE-79
6.1
2020-11-24 CVE-2020-29006 Missing Authorization vulnerability in Misp
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
network
low complexity
misp CWE-862
critical
9.8
2020-11-19 CVE-2020-28947 Cross-site Scripting vulnerability in Misp 2.4.134
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
network
low complexity
misp CWE-79
6.1
2020-11-02 CVE-2020-28043 Server-Side Request Forgery (SSRF) vulnerability in Misp
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
network
low complexity
misp CWE-918
7.5