Misp

Misp

147 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 15.09.2026 09:14:43
  • Zuletzt bearbeitet 16.09.2026 13:42:48

Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist()  - ServersCont...

  • EPSS 0.26%
  • Veröffentlicht 15.09.2026 08:50:01
  • Zuletzt bearbeitet 16.09.2026 13:42:48

Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one of the curre...

  • EPSS 0.21%
  • Veröffentlicht 15.09.2026 08:36:22
  • Zuletzt bearbeitet 16.09.2026 13:42:48

Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselves only store...

  • EPSS 0.24%
  • Veröffentlicht 15.09.2026 08:06:32
  • Zuletzt bearbeitet 16.09.2026 13:42:48

Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If th...

  • EPSS 0.16%
  • Veröffentlicht 15.09.2026 07:41:37
  • Zuletzt bearbeitet 16.09.2026 13:42:48

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For ...

  • EPSS 0.46%
  • Veröffentlicht 14.09.2026 13:22:07
  • Zuletzt bearbeitet 16.09.2026 13:42:47

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() input validation...

  • EPSS 0.23%
  • Veröffentlicht 14.09.2026 13:03:01
  • Zuletzt bearbeitet 16.09.2026 13:42:47

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images. While scripts inside SVG do not execute when the SVG is render...

  • EPSS 0.11%
  • Veröffentlicht 14.09.2026 12:37:54
  • Zuletzt bearbeitet 16.09.2026 13:42:47

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior ...

  • EPSS 0.15%
  • Veröffentlicht 14.09.2026 09:40:55
  • Zuletzt bearbeitet 16.09.2026 13:42:47

Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web application in multip...

  • EPSS 0.19%
  • Veröffentlicht 14.09.2026 09:12:03
  • Zuletzt bearbeitet 16.09.2026 13:42:47

MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomePage, and eventIndexColumnToggle were explicitly added to the Security component's unlockedActions list, which disabled all CS...