iglocska
99 exploits
Active since Sep 2016
MISP 2.4.108 - Improper Privilege Management via Organization Admin Password Reset
CVSS 6.6
MISP 2.4.109 - Authenticated Remote Code Execution via PHAR Deserialization
CVSS 7.2
MISP <2.4.115 - Privilege Escalation
CVSS 6.5
MISP 2.4.118 - Unauthenticated Tag Restriction Bypass
CVSS 5.3
MISP 2.4.102 - Authenticated Missing Authorization for Sighting Visibility
CVSS 5.3
MISP < 2.4.124 - Authenticated Sensitive Data Exposure via Feed File Ingestion
CVSS 4.9
MISP < 2.4.126 - Cross-Site Scripting in Resolved Attributes View
CVSS 6.1
MISP 2.4.127 - Missing Authorization in Attribute RestSearch API
CVSS 7.5
MISP < 2.4.129 - Cross-Site Request Forgery in Homepage Setting
CVSS 8.8
MISP v2.4.128 - Cross-Site Scripting in UserSettingsController SetHomePage Path Parameter
CVSS 6.1
MISP < 2.4.133 - Server-Side Request Forgery via REST Client use_full_path Parameter
CVSS 7.5
MISP < 2.4.121 - Time-of-check Time-of-use Race Condition in Brute-Force Protection
CVSS 5.9
MISP < 2.4.121 - Brute-Force Attack via Username Canonicalization Bypass
CVSS 5.9
MISP < 2.4.121 - Brute-Force Protection Bypass via HTTP PUT Method
CVSS 8.1
MISP < 2.4.121 - Access Control List Bypass in Discussion Threads
CVSS 6.5
MISP 2.4.136 - Weak Password Recovery Mechanism
CVSS 9.1
MISP 2.4.136 - Stored Cross-Site Scripting in Galaxy Cluster View
CVSS 6.1
MISP 2.4.136 - Stored Cross-Site Scripting via Galaxy Cluster Element Values
CVSS 6.1
MISP < 2.4.139 - Unintended Sharing Group Access via 'all org' Flag
CVSS 5.5
MISP 2.4.141 - Information Disclosure via Incorrect Sharing Group Association
CVSS 7.5
MISP 2.4.136 - Stored Cross-Site Scripting via User Homepage Favourite Button
CVSS 6.1
MISP < 2.4.148 - OS Command Injection via Opendata Export Parameter
CVSS 9.8
cerebrate < 1.4 - Reflected Cross-Site Scripting in Form Descriptions
CVSS 6.1
Cerebrate < 1.4 - Incorrect Authorization via Sharing Group ACL
CVSS 4.3
cerebrate < 1.4 - Unauthenticated Endpoint Access via Open Prefix Bypass
CVSS 5.3