Vulnerabilities > Misp

DATE CVE VULNERABILITY TITLE RISK
2017-11-25 CVE-2017-16946 Information Exposure Through Log Files vulnerability in Misp 2.4.82
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
network
low complexity
misp CWE-532
4.9
2017-08-24 CVE-2017-13671 Cross-site Scripting vulnerability in Misp
app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments.
network
low complexity
misp CWE-79
6.1