iglocska
126 exploits
Active since Sep 2016
MISP: Improper sharing group authorization check when adding attributes
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core - Cross-Organization Data Modification and Deletion
CVSS 8.8
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core - Cross-Organization Data Modification and Deletion
CVSS 8.8
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core - Cross-Organization Data Modification and Deletion
CVSS 8.8
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core Bulk Deletion - Unauthorized Event Report and Sharing Group Deletion
CVSS 8.8
MISP Core - Cross-Organization Data Modification and Deletion
CVSS 8.8
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
MISP Core Bulk Deletion - Unauthorized Event Report and Sharing Group Deletion
CVSS 8.8
MISP Core - Cross-Organization Data Modification and Deletion
CVSS 8.8
MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log Injection
CVSS 8.8
Authenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISP
CVSS 7.2