VendorsMISP-Projectmisp2.4.128
Vulnerabilities

MISP-Project MISP Project MISP (Malware Information Sharing Platform) 2.4.128

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-15411
An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.
Published 2020-06-30 · Modified
9.8EPSS 0.015
CVE-2020-24085
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code.
Published 2021-01-20 · Modified
6.1EPSS 0.008
CVE-2020-15412
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
Published 2020-06-30 · Modified
4.3EPSS 0.007