Page 3 of 102 results (0.007 seconds)

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

30 Jun 2023 — In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts. MISP version 2.4.171 suffers from a persistent cross site scripting vulnerability. • https://packetstorm.news/files/id/176975 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

27 Mar 2023 — In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index. • https://github.com/MISP/MISP/commit/b94c7978e5e6b1db369abeedbbf00bca975b08b7 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

18 Mar 2023 — js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips. • https://github.com/MISP/MISP/commit/30255b8d683df4ec54f856282b3bde9106d5ae1a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

18 Mar 2023 — js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip. • https://github.com/MISP/MISP/commit/78f423451a4c795991e739ee970bc5215c061591 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

20 Feb 2023 — app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters. • https://github.com/MISP/MISP/commit/1edbc2569989f844799261a5f90edfa433d7dbcc • CWE-755: Improper Handling of Exceptional Conditions •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

20 Feb 2023 — MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php. • https://github.com/MISP/MISP/commit/a73c1c461bc6f8a048eae92b5e99823afd892d1e • CWE-755: Improper Handling of Exceptional Conditions •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

23 Jan 2023 — app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field. app/View/AuthKeys/authkey_display.ctp en MISP hasta 2.4.167 tiene un XSS en authkey agregado a través de un campo Referer. • https://github.com/MISP/MISP/commit/f7238fe5e71ac065daa43c8607d02f8ac682f18f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

20 Jan 2023 — In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function. En MISP 2.4.167, app/Controller/Component/ACLComponent.php tiene un control de acceso incorrecto para la función de importación en decadencia. • https://github.com/MISP/MISP/commit/93bf15d3bd703a32ebfe86cb6c1c9b735cf23e30 •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

20 Jan 2023 — In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload. En MISP 2.4.167, app/webroot/js/event-graph.js tiene una vulnerabilidad XSS a través de un payload de vista previa del gráfico de eventos. • https://github.com/MISP/MISP/commit/a46f794a136001101cbec84fccf3cc824e983493 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

20 Jan 2023 — In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name. En MISP 2.4.167, app/webroot/js/action_table.js permite XSS a través de un nombre de historial de red. • https://github.com/MISP/MISP/commit/72c5424034c378583d128fc1e769aae33fb1c8b9 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •