Vulnerabilities
Vulnerable Software
Misp:  >> Misp  >> 2.4.136  Security Vulnerabilities
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
CVSS Score
9.1
EPSS Score
0.003
Published
2021-01-19
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-01-19
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
CVSS Score
6.1
EPSS Score
0.004
Published
2021-01-19
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-01-19


Contact Us

Shodan ® - All rights reserved