CVE-2022-48329
- EPSS 0.52%
- Veröffentlicht 20.02.2023 04:15:11
- Zuletzt bearbeitet 18.03.2025 16:15:14
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
CVE-2022-48328
- EPSS 0.64%
- Veröffentlicht 20.02.2023 04:15:11
- Zuletzt bearbeitet 21.11.2024 07:33:10
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
CVE-2023-24027
- EPSS 0.34%
- Veröffentlicht 20.01.2023 22:15:10
- Zuletzt bearbeitet 02.04.2025 17:15:36
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
CVE-2022-29528
- EPSS 0.52%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:15
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
CVE-2022-29529
- EPSS 0.36%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
CVE-2022-29530
- EPSS 0.36%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
CVE-2022-29531
- EPSS 0.36%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
CVE-2022-29532
- EPSS 0.3%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.
CVE-2022-29533
- EPSS 0.31%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."
CVE-2022-29534
- EPSS 0.25%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.