Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2023-48659

Disclosure Date: November 17, 2023 (last updated November 23, 2023)
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
Attacker Value
Unknown

CVE-2023-48658

Disclosure Date: November 17, 2023 (last updated November 23, 2023)
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
Attacker Value
Unknown

CVE-2023-48657

Disclosure Date: November 17, 2023 (last updated January 10, 2024)
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
Attacker Value
Unknown

CVE-2023-48656

Disclosure Date: November 17, 2023 (last updated January 10, 2024)
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
Attacker Value
Unknown

CVE-2023-48655

Disclosure Date: November 17, 2023 (last updated January 10, 2024)
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
Attacker Value
Unknown

CVE-2023-37307

Disclosure Date: June 30, 2023 (last updated January 09, 2024)
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
Attacker Value
Unknown

CVE-2023-37306

Disclosure Date: June 30, 2023 (last updated October 08, 2023)
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
Attacker Value
Unknown

CVE-2023-28884

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
Attacker Value
Unknown

CVE-2023-28607

Disclosure Date: March 18, 2023 (last updated October 08, 2023)
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
Attacker Value
Unknown

CVE-2023-28606

Disclosure Date: March 18, 2023 (last updated October 08, 2023)
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.