Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2017-16946

Disclosure Date: November 25, 2017 (last updated November 26, 2024)
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
0
Attacker Value
Unknown

CVE-2017-16802

Disclosure Date: November 13, 2017 (last updated November 26, 2024)
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
0