Sami Mokaddem
23 exploits
Active since Feb 2022
cerebrate < 1.4 - Cross-Site Scripting in Bookmarks Component
CVSS 6.1
cerebrate < 1.4 - Cross-Site Scripting in Bookmarks Component
CVSS 6.1
MISP < 2.4.164 - Incorrect Authorization in UsersController
CVSS 4.3
MISP 2.4.167 - Stored Cross-Site Scripting in Event-Graph Preview
CVSS 6.1
MISP 2.4.167 - Stored Cross-Site Scripting via Network History Name
CVSS 6.1
MISP <2.4.167 - Privilege Escalation
CVSS 9.8
MISP < 2.4.167 - Cross-Site Scripting via Referer Field in AuthKey Add
CVSS 6.1
cerebrate 1.12 - Unauthenticated API Key Creation via Missing Organisation ID Check
CVSS 9.1
MISP < 2.4.169 - Cross-Site Scripting via Event-Graph Node Tooltips
CVSS 6.1
MISP < 2.4.169 - Cross-Site Scripting in Event-Graph Relationship Tooltip
CVSS 6.1
Cerebrate 1.13 - Blind SQL Injection via SearchAll API Endpoint
CVSS 9.8
MISP 2.4.169 - Cross-Site Scripting in Community Index
CVSS 6.1
MISP < 2.4.172 - Stored Cross-Site Scripting in title_for_layout
CVSS 5.4
MISP 2.4.174 - Cross-Site Scripting in Events Index View
CVSS 6.1
cerebrate < 1.15 - Missing Secure Attribute for Session Cookie
CVSS 5.3
MISP < 2.4.179 - Cross-Site Scripting in Event Timeline Widget
CVSS 6.1
MISP < 2.4.184 - Unrestricted Upload of File with Dangerous Type via Organisation Logo Upload
CVSS 9.8
MISP < 2.4.184 - Unauthenticated Export Generation via GET Request
CVSS 9.8
MISP < 2.4.198 - Incorrect Authorization in UserLoginProfilesController
CVSS 4.9
MISP through 2.5.2 - Stored Cross-Site Scripting in Galaxy Cluster Export
CVSS 6.1
MISP through 2.5.2 - Stored Cross-Site Scripting in Workflows Editor
CVSS 6.1
Cerebrate <1.30 - Privilege Escalation
MISP < 2.5.27 - Authenticated Path Traversal in EventReport Picture View
CVSS 4.1