Sami Mokaddem

33 exploits Active since Feb 2022
CVE-2023-49926 WRITEUP MEDIUM WRITEUP
MISP < 2.4.179 - Cross-Site Scripting in Event Timeline Widget
app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.
CVSS 6.1
CVE-2024-25674 WRITEUP CRITICAL WRITEUP
MISP < 2.4.184 - Unrestricted Upload of File with Dangerous Type via Organisation Logo Upload
An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.
CVSS 9.8
CVE-2024-25675 WRITEUP CRITICAL WRITEUP
MISP < 2.4.184 - Unauthenticated Export Generation via GET Request
An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.
CVSS 9.8
CVE-2024-46918 WRITEUP MEDIUM WRITEUP
MISP < 2.4.198 - Incorrect Authorization in UserLoginProfilesController
app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.
CVSS 4.9
CVE-2024-54674 WRITEUP MEDIUM WRITEUP
MISP through 2.5.2 - Stored Cross-Site Scripting in Galaxy Cluster Export
app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom clusters into the misp-galaxy format.
CVSS 6.1
CVE-2024-54675 WRITEUP MEDIUM WRITEUP
MISP through 2.5.2 - Stored Cross-Site Scripting in Workflows Editor
app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow.
CVSS 6.1
CVE-2025-66385 WRITEUP CRITICAL WRITEUP
Cerebrate <1.30 - Privilege Escalation
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request.
CVE-2025-66386 WRITEUP MEDIUM WRITEUP
MISP < 2.5.27 - Authenticated Path Traversal in EventReport Picture View
app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.
CVSS 4.1