Misp

Misp

45 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 12.06.2026 20:30:25
  • Zuletzt bearbeitet 15.06.2026 20:46:57

MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using organisation-controlled fields such as id, name, and uuid without ensuring that the resolved file remai...

  • EPSS 0.38%
  • Veröffentlicht 12.06.2026 20:21:48
  • Zuletzt bearbeitet 15.06.2026 20:46:57

A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-controlled path value through setSettingInternal(), bypassing the normal setSetting() validation logic, inc...

  • EPSS 0.21%
  • Veröffentlicht 12.06.2026 20:08:55
  • Zuletzt bearbeitet 15.06.2026 20:46:57

An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view galaxies that should not have been visible to their organisation. The custom access-control condition intended to restrict galaxie...

  • EPSS 0.26%
  • Veröffentlicht 12.06.2026 19:59:58
  • Zuletzt bearbeitet 15.06.2026 20:46:57

MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that should have remained server-controlled, i...

  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 19:51:44
  • Zuletzt bearbeitet 15.06.2026 20:46:57

A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id field before saving the submitted data. In CakePHP, supplying a primary key in the s...

  • EPSS 0.19%
  • Veröffentlicht 12.06.2026 19:44:24
  • Zuletzt bearbeitet 15.06.2026 20:46:57

MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or AJAX requests are not restricted based on the browser-...

  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 19:34:49
  • Zuletzt bearbeitet 15.06.2026 20:46:57

An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administrative email functionality. The affected code restricted organization a...

  • EPSS 0.25%
  • Veröffentlicht 12.06.2026 19:25:32
  • Zuletzt bearbeitet 15.06.2026 20:46:57

An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to site administrator accounts within the same organization. The affected access-control checks scoped adm...

  • EPSS 0.24%
  • Veröffentlicht 04.06.2026 14:39:44
  • Zuletzt bearbeitet 04.06.2026 16:20:27

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from ...

  • EPSS 0.18%
  • Veröffentlicht 04.06.2026 13:54:34
  • Zuletzt bearbeitet 22.06.2026 19:23:18

A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New Users and New Organisations widgets. In some cases, requesting a field set that became emp...