Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2021-25323

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
Attacker Value
Unknown

CVE-2021-3184

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
Attacker Value
Unknown

CVE-2021-25325

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
Attacker Value
Unknown

CVE-2021-25324

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.