Product
misp project malware information sharing platform
16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-48659
CVE-2023-48658
CVE-2023-48657
CVE-2023-48656
CVE-2023-48655
CVE-2023-37307
CVE-2023-37306
CVE-2023-28884
CVE-2023-28607
CVE-2023-28606
CVE-2023-24070
CVE-2022-47928
CVE-2022-42724
CVE-2015-5721
CVE-2015-5720
CVE-2015-5719
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore,
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
< 2.4.176
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out que
< 2.4.172
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
all versions
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because
all versions
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
< 2.4.169
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
< 2.4.169
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
<= 2.4.167
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
< 2.4.167
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
< 2.4.164
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only t
<= 2.3.89
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via craf
<= 2.3.89
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP
<= 2.3.91
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict fil