CVE-2022-48328
- EPSS 0.64%
- Veröffentlicht 20.02.2023 04:15:11
- Zuletzt bearbeitet 21.11.2024 07:33:10
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
CVE-2023-24027
- EPSS 0.34%
- Veröffentlicht 20.01.2023 22:15:10
- Zuletzt bearbeitet 02.04.2025 17:15:36
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
CVE-2022-29534
- EPSS 0.25%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
CVE-2022-29533
- EPSS 0.31%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."
CVE-2022-29532
- EPSS 0.3%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.
CVE-2022-29531
- EPSS 0.36%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
CVE-2022-29530
- EPSS 0.36%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
CVE-2022-29529
- EPSS 0.36%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:16
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
CVE-2022-29528
- EPSS 0.52%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:15
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
CVE-2022-27245
- EPSS 0.33%
- Veröffentlicht 18.03.2022 18:15:16
- Zuletzt bearbeitet 21.11.2024 06:55:29
An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.