Filtered by vendor Misp-project
Subscriptions
Total
24 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-42724 | 1 Misp-project | 1 Malware Information Sharing Platform | 2024-11-21 | 4.3 Medium |
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have). | ||||
CVE-2018-8949 | 1 Misp-project | 1 Misp | 2024-11-21 | N/A |
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) could overwrite an existing attribute. | ||||
CVE-2018-8948 | 1 Misp-project | 1 Misp | 2024-11-21 | N/A |
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module. | ||||
CVE-2018-11245 | 1 Misp-project | 1 Misp | 2024-11-21 | N/A |
app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes. |