CVE-2023-24028
- EPSS 0.7%
- Veröffentlicht 20.01.2023 22:15:10
- Zuletzt bearbeitet 03.04.2025 15:15:47
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
CVE-2022-47928
- EPSS 0.42%
- Veröffentlicht 22.12.2022 23:15:10
- Zuletzt bearbeitet 23.06.2026 13:42:00
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
CVE-2022-42724
- EPSS 0.45%
- Veröffentlicht 10.10.2022 05:15:09
- Zuletzt bearbeitet 23.06.2026 13:42:00
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).
CVE-2022-29528
- EPSS 2.08%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 22.06.2026 19:23:18
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
CVE-2022-29529
- EPSS 0.79%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 22.06.2026 19:23:18
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
CVE-2022-29530
- EPSS 0.79%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 22.06.2026 19:23:18
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
CVE-2022-29531
- EPSS 0.79%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 22.06.2026 19:23:18
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
CVE-2022-29532
- EPSS 0.8%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 22.06.2026 19:23:18
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.
CVE-2022-29533
- EPSS 0.78%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 22.06.2026 19:23:18
An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."
CVE-2022-29534
- EPSS 1.52%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 22.06.2026 19:23:18
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.