Show filters
96 Total Results
Displaying 11-20 of 96
Sort by:
Attacker Value
Unknown

CVE-2023-48655

Disclosure Date: November 17, 2023 (last updated January 10, 2024)
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
Attacker Value
Unknown

CVE-2023-41098

Disclosure Date: August 23, 2023 (last updated October 08, 2023)
An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.
Attacker Value
Unknown

CVE-2023-40224

Disclosure Date: August 10, 2023 (last updated November 17, 2023)
MISP 2.4.174 allows XSS in app/View/Events/index.ctp.
Attacker Value
Unknown

CVE-2023-37307

Disclosure Date: June 30, 2023 (last updated January 09, 2024)
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
Attacker Value
Unknown

CVE-2023-37306

Disclosure Date: June 30, 2023 (last updated October 08, 2023)
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
Attacker Value
Unknown

CVE-2023-28884

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
Attacker Value
Unknown

CVE-2023-28607

Disclosure Date: March 18, 2023 (last updated October 08, 2023)
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
Attacker Value
Unknown

CVE-2023-28606

Disclosure Date: March 18, 2023 (last updated October 08, 2023)
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
Attacker Value
Unknown

CVE-2022-48329

Disclosure Date: February 20, 2023 (last updated October 08, 2023)
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
Attacker Value
Unknown

CVE-2022-48328

Disclosure Date: February 20, 2023 (last updated October 08, 2023)
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.