Vulnerabilities
Vulnerable Software
Misp-Project:  >> Misp  >> 2.4.147  Security Vulnerabilities
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.
CVSS Score
6.1
EPSS Score
0.006
Published
2022-03-18
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
CVSS Score
9.8
EPSS Score
0.018
Published
2021-09-17
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
CVSS Score
5.4
EPSS Score
0.006
Published
2021-07-30
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
CVSS Score
5.4
EPSS Score
0.007
Published
2021-07-30


Contact Us

Shodan ® - All rights reserved