Home/Product/misp project malware information sharing platform
Product

misp project malware information sharing platform

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-48659
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
9.8CRITICAL
CVE-2023-48658
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore,
9.8CRITICAL
CVE-2023-48657
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
9.8CRITICAL
CVE-2023-48656
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
9.8CRITICAL
CVE-2023-48655
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out que
9.8CRITICAL
CVE-2023-37307
< 2.4.172
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
5.4MEDIUM
CVE-2023-37306
all versions
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because
7.5HIGH
CVE-2023-28884
all versions
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
6.1MEDIUM
CVE-2023-28607
< 2.4.169
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
6.1MEDIUM
CVE-2023-28606
< 2.4.169
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
6.1MEDIUM
CVE-2023-24070
<= 2.4.167
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
6.1MEDIUM
CVE-2022-47928
< 2.4.167
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
6.1MEDIUM
CVE-2022-42724
< 2.4.164
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only t
4.3MEDIUM
CVE-2015-5721
<= 2.3.89
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via craf
9.8CRITICAL
CVE-2015-5720
<= 2.3.89
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP
6.1MEDIUM
CVE-2015-5719
<= 2.3.91
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict fil
9.8CRITICAL
threatengine.sh