Show filters
96 Total Results
Displaying 51-60 of 96
Sort by:
Attacker Value
Unknown

CVE-2021-25324

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
Attacker Value
Unknown

CVE-2020-29572

Disclosure Date: December 06, 2020 (last updated February 22, 2025)
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
Attacker Value
Unknown

CVE-2020-29006

Disclosure Date: November 24, 2020 (last updated February 22, 2025)
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
Attacker Value
Unknown

CVE-2020-28947

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
Attacker Value
Unknown

CVE-2020-28043

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
Attacker Value
Unknown

CVE-2020-25766

Disclosure Date: September 18, 2020 (last updated October 07, 2023)
An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.
Attacker Value
Unknown

CVE-2020-15711

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
Attacker Value
Unknown

CVE-2020-15412

Disclosure Date: June 30, 2020 (last updated February 21, 2025)
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
Attacker Value
Unknown

CVE-2020-15411

Disclosure Date: June 30, 2020 (last updated November 28, 2024)
An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.
Attacker Value
Unknown

CVE-2020-14969

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.