Show filters
96 Total Results
Displaying 91-96 of 96
Sort by:
Attacker Value
Unknown

CVE-2017-14337

Disclosure Date: September 12, 2017 (last updated November 26, 2024)
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value, the unauthenticated user can be granted access as an arbitrary user.
0
Attacker Value
Unknown

CVE-2017-13671

Disclosure Date: August 24, 2017 (last updated November 26, 2024)
app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.
0
Attacker Value
Unknown

CVE-2017-7215

Disclosure Date: March 21, 2017 (last updated November 26, 2024)
Cross site scripting in some view elements in the index filter tool in app/webroot/js/misp2.4.68.js and the organisation landing page in app/View/Organisations/ajax/landingpage.ctp of MISP before 2.4.69 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown

CVE-2015-5719

Disclosure Date: September 03, 2016 (last updated November 25, 2024)
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.
0
Attacker Value
Unknown

CVE-2015-5720

Disclosure Date: September 03, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxification.js.
0
Attacker Value
Unknown

CVE-2015-5721

Disclosure Date: September 03, 2016 (last updated November 25, 2024)
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.
0