Flowintel

Flowintel

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 27.08.2026 13:36:19
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform WTForms field validation; it merely constructs a validator object. Consequently, malformed attacker-controlled ema...

  • EPSS 0.33%
  • Veröffentlicht 27.08.2026 13:32:48
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if an attacker already possesses a valid session—for example, from prior access or a stolen session token—the victim cha...

  • EPSS 0.25%
  • Veröffentlicht 27.08.2026 13:25:08
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: * object UUID; * object name; * attribute value; * attribute type; * comment; * first/last seen values...

  • EPSS 0.29%
  • Veröffentlicht 27.08.2026 13:20:49
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id parameter identifying the user whose assignments should be returned, but previously had no role restriction beyon...

  • EPSS 0.31%
  • Veröffentlicht 27.08.2026 13:14:20
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authorization check correctly prevented an organization administrator from editing users in another organization, but it did not prevent ...

  • EPSS 0.21%
  • Veröffentlicht 27.08.2026 13:10:30
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints. The routes generally received both a case identifier and a task identifier, but previously they did...

  • EPSS 0.26%
  • Veröffentlicht 27.08.2026 12:48:39
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify a case title could store HTML or script-capable content that is later interpreted by the b...

  • EPSS 0.35%
  • Veröffentlicht 27.08.2026 12:06:18
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled markup. Because Mermaid note content is persisted and later rendered for other users, an attacker with permissio...

  • EPSS 0.32%
  • Veröffentlicht 27.08.2026 11:59:50
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without restricting it to a filename inside the intended log directory. Because the application constructs the log destination from this co...

  • EPSS 0.31%
  • Veröffentlicht 27.08.2026 10:23:01
  • Zuletzt bearbeitet 28.08.2026 15:28:32

Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration values were normalized to Python literals, the corresponding keys were used directly when constructing and replaci...