Show filters
96 Total Results
Displaying 31-40 of 96
Sort by:
Attacker Value
Unknown
CVE-2022-29530
Disclosure Date: April 20, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
0
Attacker Value
Unknown
CVE-2022-29529
Disclosure Date: April 20, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
0
Attacker Value
Unknown
CVE-2022-29528
Disclosure Date: April 20, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
0
Attacker Value
Unknown
CVE-2022-27246
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.
0
Attacker Value
Unknown
CVE-2022-27245
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.
0
Attacker Value
Unknown
CVE-2022-27244
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom auth name. This would be executed each time the administrator modifies a user.
0
Attacker Value
Unknown
CVE-2022-27243
Disclosure Date: March 18, 2022 (last updated October 07, 2023)
An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom terms file setting.
0
Attacker Value
Unknown
CVE-2021-41326
Disclosure Date: September 17, 2021 (last updated November 28, 2024)
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
0
Attacker Value
Unknown
CVE-2021-39302
Disclosure Date: August 19, 2021 (last updated February 23, 2025)
MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
0
Attacker Value
Unknown
CVE-2021-37742
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
0