Jakub Onderka

2 exploits Active since Jun 2020
CVE-2020-15412 WRITEUP MEDIUM WRITEUP
MISP <2.4.128 - Info Disclosure
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
CVSS 4.3
CVE-2020-29572 WRITEUP MEDIUM WRITEUP
MISP 2.4.135 - XSS
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
CVSS 6.1