Show filters
96 Total Results
Displaying 61-70 of 96
Sort by:
Attacker Value
Unknown
CVE-2020-13153
Disclosure Date: May 18, 2020 (last updated February 21, 2025)
app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
0
Attacker Value
Unknown
CVE-2020-12889
Disclosure Date: May 15, 2020 (last updated November 27, 2024)
MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.
0
Attacker Value
Unknown
CVE-2020-11458
Disclosure Date: April 02, 2020 (last updated November 27, 2024)
app/Model/feed.php in MISP before 2.4.124 allows administrators to choose arbitrary files that should be ingested by MISP. This does not cause a leak of the full contents of a file, but does cause a leaks of strings that match certain patterns. Among the data that can leak are passwords from database.php or GPG key passphrases from config.php.
0
Attacker Value
Unknown
CVE-2020-10246
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
0
Attacker Value
Unknown
CVE-2020-10247
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.
0
Attacker Value
Unknown
CVE-2020-8892
Disclosure Date: February 12, 2020 (last updated November 27, 2024)
An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.
0
Attacker Value
Unknown
CVE-2020-8891
Disclosure Date: February 12, 2020 (last updated November 27, 2024)
An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.
0
Attacker Value
Unknown
CVE-2020-8894
Disclosure Date: February 12, 2020 (last updated November 27, 2024)
An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php.
0
Attacker Value
Unknown
CVE-2020-8893
Disclosure Date: February 12, 2020 (last updated November 27, 2024)
An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.
0
Attacker Value
Unknown
CVE-2020-8890
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.
0