CVE-2018-8948
- EPSS 0.81%
- Veröffentlicht 23.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:40
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
CVE-2018-8949
- EPSS 0.77%
- Veröffentlicht 23.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:40
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs s...
- EPSS 1.67%
- Veröffentlicht 12.02.2018 17:29:00
- Zuletzt bearbeitet 22.06.2026 19:23:18
In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject...
CVE-2017-16946
- EPSS 1.08%
- Veröffentlicht 25.11.2017 18:29:00
- Zuletzt bearbeitet 22.06.2026 19:23:18
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
CVE-2017-16802
- EPSS 0.6%
- Veröffentlicht 13.11.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
CVE-2017-15216
- EPSS 0.84%
- Veröffentlicht 10.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.
CVE-2017-14337
- EPSS 0.93%
- Veröffentlicht 12.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value...
CVE-2017-13671
- EPSS 0.97%
- Veröffentlicht 24.08.2017 19:29:00
- Zuletzt bearbeitet 22.06.2026 19:23:18
app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.
CVE-2015-5721
- EPSS 2.61%
- Veröffentlicht 03.09.2016 20:59:02
- Zuletzt bearbeitet 23.06.2026 13:42:00
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.
CVE-2015-5720
- EPSS 1.34%
- Veröffentlicht 03.09.2016 20:59:01
- Zuletzt bearbeitet 23.06.2026 13:42:00
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edi...