Show filters
96 Total Results
Displaying 61-70 of 96
Sort by:
Attacker Value
Unknown

CVE-2020-13153

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
Attacker Value
Unknown

CVE-2020-12889

Disclosure Date: May 15, 2020 (last updated November 27, 2024)
MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.
Attacker Value
Unknown

CVE-2020-11458

Disclosure Date: April 02, 2020 (last updated November 27, 2024)
app/Model/feed.php in MISP before 2.4.124 allows administrators to choose arbitrary files that should be ingested by MISP. This does not cause a leak of the full contents of a file, but does cause a leaks of strings that match certain patterns. Among the data that can leak are passwords from database.php or GPG key passphrases from config.php.
Attacker Value
Unknown

CVE-2020-10246

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
Attacker Value
Unknown

CVE-2020-10247

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.
Attacker Value
Unknown

CVE-2020-8892

Disclosure Date: February 12, 2020 (last updated November 27, 2024)
An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.
Attacker Value
Unknown

CVE-2020-8891

Disclosure Date: February 12, 2020 (last updated November 27, 2024)
An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.
Attacker Value
Unknown

CVE-2020-8894

Disclosure Date: February 12, 2020 (last updated November 27, 2024)
An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php.
Attacker Value
Unknown

CVE-2020-8893

Disclosure Date: February 12, 2020 (last updated November 27, 2024)
An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.
Attacker Value
Unknown

CVE-2020-8890

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.