Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Misp CRITICAL 9.8
CVE-2021-35502

app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:inde…

Patch available
Fix from $2,300 2021-06-25
Misp HIGH 7.5
CVE-2021-31780

In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an ob…

Patch available
Fix from $1,950 2021-04-23
Misp MEDIUM 5.5
CVE-2021-27904

An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes pr…

Fix: after 2.4.139
Fix from $1,600 2021-03-02
Misp MEDIUM 6.1
CVE-2020-24085

A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a l…

Patch available
Fix from $1,600 2021-01-26
Misp CRITICAL 9.1
CVE-2021-25323

The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changin…

Patch available
Fix from $2,300 2021-01-19
Misp MEDIUM 6.1
CVE-2021-25324

MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.

Patch available
Fix from $1,600 2021-01-19
Misp MEDIUM 6.1
CVE-2021-25325

MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.

Patch available
Fix from $1,600 2021-01-19
Misp MEDIUM 6.1
CVE-2021-3184

MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.

Patch available
Fix from $1,600 2021-01-19
Misp MEDIUM 6.1
CVE-2020-29572

app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.

Patch available
Fix from $1,600 2020-12-06
Misp CRITICAL 9.8
CVE-2020-29006

MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.

Fix: 2.4.135+
Fix from $2,300 2020-11-24
Misp MEDIUM 6.1
CVE-2020-28947

In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.

Patch available
Fix from $1,600 2020-11-19
Misp HIGH 7.5
CVE-2020-28043

MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.

Fix: after 2.4.133
Fix from $1,950 2020-11-02
Misp HIGH 7.5
CVE-2020-25766

An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the log…

Fix: 2.4.132+
Fix from $1,950 2020-09-18
Misp HIGH 8.8
CVE-2020-15711

In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.

Fix: 2.4.129+
Fix from $1,950 2020-07-14
Misp CRITICAL 9.8
CVE-2020-15411

An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.

Patch available
Fix from $2,300 2020-06-30
Misp HIGH 7.5
CVE-2020-14969

app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, reveal…

Patch available
Fix from $1,950 2020-06-22
Misp MEDIUM 6.1
CVE-2020-13153

app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.

Fix: 2.4.126+
Fix from $1,600 2020-05-18
Misp MEDIUM 6.1
CVE-2020-10246

MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.

Patch available
Fix from $1,600 2020-03-09
Misp MEDIUM 6.1
CVE-2020-10247

MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.

Patch available
Fix from $1,600 2020-03-09
Misp HIGH 8.1
CVE-2020-8892

An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.

Fix: 2.4.121+
Fix from $1,950 2020-02-12
Misp HIGH 7.5
CVE-2020-8893

An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.

Fix: 2.4.121+
Fix from $1,950 2020-02-12
Misp MEDIUM 6.5
CVE-2020-8894

An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thr…

Fix: 2.4.121+
Fix from $1,600 2020-02-12
Misp MEDIUM 5.9
CVE-2020-8890

An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the datab…

Fix: 2.4.121+
Fix from $1,600 2020-02-12
Misp MEDIUM 5.9
CVE-2020-8891

An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.

Fix: 2.4.121+
Fix from $1,600 2020-02-12
Misp MEDIUM 5.3
CVE-2019-19379

In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.

Patch available
Fix from $1,600 2019-11-28
Misp MEDIUM 6.5
CVE-2019-16202

MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLogge…

Fix: 2.4.115+
Fix from $1,600 2019-09-10
Misp MEDIUM 6.1
CVE-2019-14286

In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view.…

Patch available
Fix from $1,600 2019-07-27
Misp HIGH 7.2
CVE-2019-12868EPSS 6%

app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-…

Patch available
Fix from $1,950 2019-06-18
Misp MEDIUM 6.6
CVE-2019-12794

An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability t…

Patch available
Fix from $1,600 2019-06-11
Misp MEDIUM 6.1
CVE-2019-11812

A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion inter…

Fix: 2.4.107+
Fix from $1,600 2019-05-08