Vulnerabilities
Vulnerable Software
Misp:  Security Vulnerabilities
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
CVSS Score
4.9
EPSS Score
0.003
Published
2017-11-25
app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-08-24


Contact Us

Shodan ® - All rights reserved