Vulnerabilities
Vulnerable Software
Misp:  >> Misp  >> 2.4.127  Security Vulnerabilities
An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.
CVSS Score
7.5
EPSS Score
0.002
Published
2020-09-18
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
CVSS Score
8.8
EPSS Score
0.001
Published
2020-07-14
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
CVSS Score
7.5
EPSS Score
0.003
Published
2020-06-22


Contact Us

Shodan ® - All rights reserved