Misp

Misp

147 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.54%
  • Veröffentlicht 22.09.2026 13:01:45
  • Zuletzt bearbeitet 22.09.2026 16:18:21

MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID list into a single-...

  • EPSS 0.44%
  • Veröffentlicht 22.09.2026 12:54:46
  • Zuletzt bearbeitet 22.09.2026 16:18:19

MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick ...

  • EPSS 0.39%
  • Veröffentlicht 22.09.2026 12:40:38
  • Zuletzt bearbeitet 22.09.2026 16:18:19

MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation and passed it to the Overmind-themed AnalystData...

  • EPSS 0.27%
  • Veröffentlicht 22.09.2026 12:31:23
  • Zuletzt bearbeitet 22.09.2026 16:18:19

MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action...

  • EPSS 0.17%
  • Veröffentlicht 21.09.2026 13:50:46
  • Zuletzt bearbeitet 21.09.2026 15:17:40

MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protection against ...

  • EPSS 0.3%
  • Veröffentlicht 21.09.2026 13:36:13
  • Zuletzt bearbeitet 21.09.2026 15:17:39

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was actually XML. Be...

  • EPSS 0.21%
  • Veröffentlicht 21.09.2026 13:25:40
  • Zuletzt bearbeitet 21.09.2026 15:17:39

When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of this, someon...

  • EPSS 0.22%
  • Veröffentlicht 21.09.2026 13:14:00
  • Zuletzt bearbeitet 21.09.2026 16:17:30

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event coul...

  • EPSS 0.33%
  • Veröffentlicht 21.09.2026 12:52:03
  • Zuletzt bearbeitet 21.09.2026 15:17:39

The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A site administ...

  • EPSS 0.25%
  • Veröffentlicht 21.09.2026 12:42:53
  • Zuletzt bearbeitet 21.09.2026 15:17:39

MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view information. However, after logging in with such a key, a specific MISP function could accidenta...