iglocska
99 exploits
Active since Sep 2016
MISP improper authorization allows organization administrators to modify site administrator user settings
MISP organization administrators can target site administrator accounts for password reset
MISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by default
MISP sharing group creation mass assignment allows unauthorized takeover of existing sharing groups
MISP mass assignment vulnerabilities allow unauthorized modification of ownership and delegation records
MISP template builder exposes non-visible custom galaxies across organisations
MISP Overmind theme stored XSS via unvalidated homepage setting
MISP organisation logo path traversal allows retrieval of arbitrary PNG/SVG files
MISP UiBeta event index reflected XSS in advanced filter popup
MISP AuthKey edit endpoint allows authenticated user email enumeration
MISP event editing allows unauthorized assignment to undisclosed sharing groups
MISP object edit authorization bypass allows unauthorized sharing group assignment
Cerebrate before v1.37 allows mass assignment of record identifiers during object creation
Cerebrate < 1.37 - Authenticated Mass Assignment Record Overwrite
Unauthorized exposure of private galaxies in MISP event template creation
CVSS 4.3
MISP Event template importer authorization bypass
CVSS 4.3
Open redirect in MISP dashboard button widget URL handling
CVSS 6.1
MISP CRUDComponent delete validation bypass via operator precedence error
CVSS 6.5
MISP post-login open redirect via pre_login_requested_url
CVSS 6.1
MISP User-controlled order parameter in correlations over-correlation endpoint
CVSS 8.1
MISP Dashboard widget field selection may expose restricted user and organisation data
CVSS 4.3
MISP user edit endpoint mass assignment vulnerability allows unauthorized user account modification
MISP: Improper UUID validation in MISP Collections
CVSS 5.3
MISP < 2.4.68 - Cross-Site Scripting in Index Filter Tool and Organisation Landing Page
CVSS 6.1
MISP 2.4.90-2.4.98 - Authenticated OS Command Injection via STIX Import Filename
CVSS 8.8