Misp

Misp

147 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 02.10.2026 15:49:32
  • Zuletzt bearbeitet 02.10.2026 17:17:04

MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can ...

  • EPSS 0.32%
  • Veröffentlicht 02.10.2026 15:21:53
  • Zuletzt bearbeitet 02.10.2026 17:17:04

MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the re...

  • EPSS 0.36%
  • Veröffentlicht 02.10.2026 15:16:27
  • Zuletzt bearbeitet 02.10.2026 17:17:04

MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated link URL but rendered the field value without HTML encoding. An attacker with th...

  • EPSS 0.22%
  • Veröffentlicht 01.10.2026 11:31:32
  • Zuletzt bearbeitet 01.10.2026 15:17:29

MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organiz...

  • EPSS 0.3%
  • Veröffentlicht 01.10.2026 08:55:51
  • Zuletzt bearbeitet 01.10.2026 16:17:38

MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sa...

  • EPSS 0.34%
  • Veröffentlicht 01.10.2026 08:48:38
  • Zuletzt bearbeitet 01.10.2026 16:17:37

MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed a user-supplied tag name value from the request unescaped into the rende...

  • EPSS 0.23%
  • Veröffentlicht 01.10.2026 08:33:05
  • Zuletzt bearbeitet 01.10.2026 16:17:37

MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attri...

  • EPSS 0.31%
  • Veröffentlicht 01.10.2026 08:08:55
  • Zuletzt bearbeitet 01.10.2026 16:17:37

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP c...

  • EPSS 0.2%
  • Veröffentlicht 01.10.2026 07:34:02
  • Zuletzt bearbeitet 01.10.2026 16:17:37

MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a counter value...

  • EPSS 0.3%
  • Veröffentlicht 30.09.2026 14:25:59
  • Zuletzt bearbeitet 30.09.2026 16:17:09

MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The ...