Show filters
96 Total Results
Displaying 11-20 of 96
Sort by:
Attacker Value
Unknown
CVE-2023-48655
Disclosure Date: November 17, 2023 (last updated January 10, 2024)
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
0
Attacker Value
Unknown
CVE-2023-41098
Disclosure Date: August 23, 2023 (last updated October 08, 2023)
An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.
0
Attacker Value
Unknown
CVE-2023-40224
Disclosure Date: August 10, 2023 (last updated November 17, 2023)
MISP 2.4.174 allows XSS in app/View/Events/index.ctp.
0
Attacker Value
Unknown
CVE-2023-37307
Disclosure Date: June 30, 2023 (last updated January 09, 2024)
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
0
Attacker Value
Unknown
CVE-2023-37306
Disclosure Date: June 30, 2023 (last updated October 08, 2023)
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
0
Attacker Value
Unknown
CVE-2023-28884
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
0
Attacker Value
Unknown
CVE-2023-28607
Disclosure Date: March 18, 2023 (last updated October 08, 2023)
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
0
Attacker Value
Unknown
CVE-2023-28606
Disclosure Date: March 18, 2023 (last updated October 08, 2023)
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
0
Attacker Value
Unknown
CVE-2022-48329
Disclosure Date: February 20, 2023 (last updated October 08, 2023)
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
0
Attacker Value
Unknown
CVE-2022-48328
Disclosure Date: February 20, 2023 (last updated October 08, 2023)
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
0