Misp

Misp

45 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 13.05.2026 20:53:36
  • Zuletzt bearbeitet 22.06.2026 19:23:18

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or modify Collection records could submit malformed UUID...

  • EPSS 0.4%
  • Veröffentlicht 13.05.2026 20:51:30
  • Zuletzt bearbeitet 22.06.2026 19:23:18

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys ...

  • EPSS 0.23%
  • Veröffentlicht 13.05.2026 20:50:04
  • Zuletzt bearbeitet 22.06.2026 19:23:18

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code acce...

  • EPSS 0.14%
  • Veröffentlicht 07.05.2026 12:16:18
  • Zuletzt bearbeitet 22.06.2026 19:23:18

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in the template e...

  • EPSS 0.35%
  • Veröffentlicht 09.04.2026 17:16:30
  • Zuletzt bearbeitet 22.06.2026 19:23:18

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.a...

  • EPSS 0.27%
  • Veröffentlicht 15.12.2025 03:25:46
  • Zuletzt bearbeitet 22.06.2026 19:23:18

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

  • EPSS 0.26%
  • Veröffentlicht 28.11.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.

  • EPSS 0.31%
  • Veröffentlicht 28.11.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.

  • EPSS 0.2%
  • Veröffentlicht 28.03.2025 22:15:17
  • Zuletzt bearbeitet 22.06.2026 19:23:18

In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.

  • EPSS 0.19%
  • Veröffentlicht 28.03.2025 22:15:17
  • Zuletzt bearbeitet 22.06.2026 19:23:18

In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.