RSS   Vulnerabilities for 'MISP'   RSS

2018-05-18
 
CVE-2018-11245

CWE-79
 

 
app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.

 
2017-11-13
 
CVE-2017-16802

CWE-79
 

 
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.

 
2017-10-10
 
CVE-2017-15216

CWE-79
 

 
IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications (IBM BigFix Platform 9.2 and 9.5) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129831.

 
2017-09-12
 
CVE-2017-14337

 

 
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value, the unauthenticated user can be granted access as an arbitrary user.

 

 >>> Vendor: Misp-project 2 Products
Malware information sharing platform
MISP


Copyright 2024, cxsecurity.com

 

Back to Top