Vulnerabilities
Vulnerable Software
Misp-Project:  >> Misp  Security Vulnerabilities
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
CVSS Score
9.8
EPSS Score
0.018
Published
2021-09-17
MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
CVSS Score
9.8
EPSS Score
0.009
Published
2021-08-19
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
CVSS Score
5.4
EPSS Score
0.006
Published
2021-07-30
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
CVSS Score
5.4
EPSS Score
0.007
Published
2021-07-30
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
CVSS Score
5.4
EPSS Score
0.005
Published
2021-07-26
app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
CVSS Score
6.1
EPSS Score
0.006
Published
2021-07-07
app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.
CVSS Score
9.8
EPSS Score
0.011
Published
2021-06-25
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused.
CVSS Score
7.5
EPSS Score
0.01
Published
2021-04-23
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.
CVSS Score
5.5
EPSS Score
0.003
Published
2021-03-02
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code.
CVSS Score
6.1
EPSS Score
0.008
Published
2021-01-26


Contact Us

Shodan ® - All rights reserved