Vulnerabilities > Misp > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-01-19 | CVE-2021-25325 | Cross-site Scripting vulnerability in Misp 2.4.136 MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. | 4.3 |
2021-01-19 | CVE-2021-25324 | Cross-site Scripting vulnerability in Misp 2.4.136 MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp. | 4.3 |
2021-01-19 | CVE-2021-25323 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Misp 2.4.136 The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password. | 6.4 |
2020-12-06 | CVE-2020-29572 | Cross-site Scripting vulnerability in Misp 2.4.135 app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field. | 4.3 |
2020-11-19 | CVE-2020-28947 | Cross-site Scripting vulnerability in Misp 2.4.134 In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled. | 4.3 |
2020-11-02 | CVE-2020-28043 | Server-Side Request Forgery (SSRF) vulnerability in Misp MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL. | 5.0 |
2020-09-18 | CVE-2020-25766 | Unspecified vulnerability in Misp An issue was discovered in MISP before 2.4.132. | 5.0 |
2020-07-14 | CVE-2020-15711 | Cross-Site Request Forgery (CSRF) vulnerability in Misp In MISP before 2.4.129, setting a favourite homepage was not CSRF protected. | 6.8 |
2020-06-30 | CVE-2020-15412 | Improper Privilege Management vulnerability in Misp 2.4.128 An issue was discovered in MISP 2.4.128. | 4.0 |
2020-06-22 | CVE-2020-14969 | Information Exposure vulnerability in Misp 2.4.127 app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. | 5.0 |