Vulnerabilities
Vulnerable Software
Misp:  >> Misp  >> 2.4.105  Security Vulnerabilities
MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115)" message.
CVSS Score
6.5
EPSS Score
0.002
Published
2019-09-10
A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-05-08
An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes with javascript:// links.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-05-08
An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-05-08


Contact Us

Shodan ® - All rights reserved