Show filters
96 Total Results
Displaying 41-50 of 96
Sort by:
Attacker Value
Unknown
CVE-2021-37743
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
0
Attacker Value
Unknown
CVE-2021-37534
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
0
Attacker Value
Unknown
CVE-2021-36212
Disclosure Date: July 07, 2021 (last updated February 22, 2025)
app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
0
Attacker Value
Unknown
CVE-2021-35502
Disclosure Date: June 25, 2021 (last updated November 28, 2024)
app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.
0
Attacker Value
Unknown
CVE-2021-31780
Disclosure Date: April 23, 2021 (last updated February 22, 2025)
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused.
0
Attacker Value
Unknown
CVE-2021-27904
Disclosure Date: March 02, 2021 (last updated November 28, 2024)
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.
0
Attacker Value
Unknown
CVE-2020-24085
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code.
0
Attacker Value
Unknown
CVE-2021-25323
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
0
Attacker Value
Unknown
CVE-2021-3184
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
0
Attacker Value
Unknown
CVE-2021-25325
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
0