VendorsMISP-Projectmisp2.4.136
Vulnerabilities

MISP-Project MISP Project MISP (Malware Information Sharing Platform) 2.4.136

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-25323
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
Published 2021-01-19 · Modified
9.1EPSS 0.013
CVE-2021-25324
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
Published 2021-01-19 · Modified
6.1EPSS 0.008
CVE-2021-25325
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
Published 2021-01-19 · Modified
6.1EPSS 0.008
CVE-2021-3184
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
Published 2021-01-19 · Modified
6.1EPSS 0.008