Misp

Misp

50 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.6%
  • Veröffentlicht 22.06.2026 11:43:02
  • Zuletzt bearbeitet 22.06.2026 18:16:49

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and rela...

  • EPSS 0.22%
  • Veröffentlicht 12.06.2026 21:08:15
  • Zuletzt bearbeitet 23.07.2026 09:10:00

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or vi...

  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 20:55:53
  • Zuletzt bearbeitet 15.06.2026 20:46:57

A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data and set an event’s sharing_group_id to a sharing group they were not authorized to use. When distrib...

  • EPSS 0.25%
  • Veröffentlicht 12.06.2026 20:48:18
  • Zuletzt bearbeitet 15.06.2026 20:46:57

An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit request, the user dropdown was populated using the attacker-controlled AuthKey.user_id value from the submitt...

  • EPSS 0.26%
  • Veröffentlicht 12.06.2026 20:36:09
  • Zuletzt bearbeitet 15.06.2026 20:46:57

MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScript handler using HTML escaping inside a single-quoted JavaScript string. Because browsers HTML-decode ...

  • EPSS 0.32%
  • Veröffentlicht 12.06.2026 20:30:25
  • Zuletzt bearbeitet 15.06.2026 20:46:57

MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using organisation-controlled fields such as id, name, and uuid without ensuring that the resolved file remai...

  • EPSS 0.38%
  • Veröffentlicht 12.06.2026 20:21:48
  • Zuletzt bearbeitet 15.06.2026 20:46:57

A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-controlled path value through setSettingInternal(), bypassing the normal setSetting() validation logic, inc...

  • EPSS 0.21%
  • Veröffentlicht 12.06.2026 20:08:55
  • Zuletzt bearbeitet 15.06.2026 20:46:57

An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view galaxies that should not have been visible to their organisation. The custom access-control condition intended to restrict galaxie...

  • EPSS 0.26%
  • Veröffentlicht 12.06.2026 19:59:58
  • Zuletzt bearbeitet 15.06.2026 20:46:57

MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that should have remained server-controlled, i...

  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 19:51:44
  • Zuletzt bearbeitet 15.06.2026 20:46:57

A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id field before saving the submitted data. In CakePHP, supplying a primary key in the s...