Misp

Misp

50 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 12.06.2026 19:44:24
  • Zuletzt bearbeitet 15.06.2026 20:46:57

MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or AJAX requests are not restricted based on the browser-...

  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 19:34:49
  • Zuletzt bearbeitet 15.06.2026 20:46:57

An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administrative email functionality. The affected code restricted organization a...

  • EPSS 0.25%
  • Veröffentlicht 12.06.2026 19:25:32
  • Zuletzt bearbeitet 15.06.2026 20:46:57

An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to site administrator accounts within the same organization. The affected access-control checks scoped adm...

  • EPSS 0.24%
  • Veröffentlicht 04.06.2026 14:39:44
  • Zuletzt bearbeitet 22.07.2026 20:10:00

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from ...

  • EPSS 0.18%
  • Veröffentlicht 04.06.2026 13:54:34
  • Zuletzt bearbeitet 22.07.2026 20:10:00

A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New Users and New Organisations widgets. In some cases, requesting a field set that became emp...

  • EPSS 0.23%
  • Veröffentlicht 04.06.2026 13:44:49
  • Zuletzt bearbeitet 22.07.2026 20:10:00

A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-co...

  • EPSS 0.2%
  • Veröffentlicht 04.06.2026 13:34:27
  • Zuletzt bearbeitet 22.07.2026 20:10:00

A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === nu...

  • EPSS 0.22%
  • Veröffentlicht 04.06.2026 13:26:05
  • Zuletzt bearbeitet 22.07.2026 20:10:00

An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination without sufficiently enforcing that it was a local a...

  • EPSS 0.15%
  • Veröffentlicht 04.06.2026 13:17:47
  • Zuletzt bearbeitet 22.07.2026 20:10:00

A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted by browsers as an external URL. The validation rejected URLs containing an explicit scheme, host, ...

  • EPSS 0.15%
  • Veröffentlicht 04.06.2026 13:05:48
  • Zuletzt bearbeitet 22.07.2026 20:10:00

An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user b...