Luciano Righetti
14 exploits
Active since Jul 2021
OTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authentication is enabled
CVSS 10.0
MISP OIDC authentication bypass via automatic email-based account linking under insecure IdP configurations
MISP core - Stored XSS in MISP template (old engine) element attribute type
CVSS 5.4
LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
CVSS 9.6
LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
CVSS 9.6
MISP < 2.4.146 - Stored Cross-Site Scripting in Sharing Groups View
CVSS 6.1
MISP 2.4.148 - SQL Injection via Log.php $conditions['org'] Value
CVSS 9.8
MISP < 2.4.156 - Local File Inclusion via Custom Terms File Setting
CVSS 7.8
MISP < 2.4.156 - Server-Side Request Forgery via generateServerSettings
CVSS 8.8
MISP < 2.4.156 - Stored Cross-Site Scripting via SVG Org Logo Upload
CVSS 6.1
MISP 2.4.172 - Sensitive Information Exposure via Certificate File Extension Error Messages
CVSS 7.5
MISP 2.4.174 - Reflected Cross-Site Scripting via Dashboard Edit ID Parameter
CVSS 6.1
MISP < 2.4.176 - SQL Injection via Improper Filtering of Query Parameters
CVSS 9.8
MISP < 2.4.176 - SQL Injection via Order Parameter
CVSS 9.8