← Back

Misp Project

misp-project

25 CVEs • 2 products

Products (2)

Click to collapse
Toggle

CVEs (25)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Nov 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Nov 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Nov 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Nov 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Nov 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Jun 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Jun 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Mar 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
1Misp Project
1Malware Information Sharing Platform
Feb 26, 2025
Mar 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
1Misp Project
1Malware Information Sharing Platform
Feb 26, 2025
Mar 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Jan 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
1Misp Project
1Misp
Apr 3, 2025
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
1Misp Project
1Misp
Apr 2, 2025
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Dec 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
1Misp Project
1Malware Information Sharing Platform
Nov 21, 2024
Oct 10, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).
1Misp Project
1Misp
Nov 21, 2024
May 18, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.
1Misp Project
1Misp
Nov 21, 2024
Mar 23, 2018
N/A· v4
4.3 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attri...Show more
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) could overwrite an existing attribute.Show less
1Misp Project
1Misp
Nov 21, 2024
Mar 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
1Misp Project
1Misp
May 13, 2026
Nov 13, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
1Misp Project
1Misp
May 13, 2026
Oct 10, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.