Show filters
96 Total Results
Displaying 31-40 of 96
Sort by:
Attacker Value
Unknown

CVE-2022-29530

Disclosure Date: April 20, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
Attacker Value
Unknown

CVE-2022-29529

Disclosure Date: April 20, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
Attacker Value
Unknown

CVE-2022-29528

Disclosure Date: April 20, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
Attacker Value
Unknown

CVE-2022-27246

Disclosure Date: March 18, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.
Attacker Value
Unknown

CVE-2022-27245

Disclosure Date: March 18, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.
Attacker Value
Unknown

CVE-2022-27244

Disclosure Date: March 18, 2022 (last updated February 23, 2025)
An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom auth name. This would be executed each time the administrator modifies a user.
Attacker Value
Unknown

CVE-2022-27243

Disclosure Date: March 18, 2022 (last updated October 07, 2023)
An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom terms file setting.
Attacker Value
Unknown

CVE-2021-41326

Disclosure Date: September 17, 2021 (last updated November 28, 2024)
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
Attacker Value
Unknown

CVE-2021-39302

Disclosure Date: August 19, 2021 (last updated February 23, 2025)
MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
Attacker Value
Unknown

CVE-2021-37742

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.