VendorsMISP-Projectmisp2.4.82
Vulnerabilities

MISP-Project MISP Project MISP (Malware Information Sharing Platform) 2.4.82

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2017-16802
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
Published 2017-11-13 · Modified
5.4EPSS 0.006
CVE-2017-16946
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
Published 2017-11-25 · Modified
4.9EPSS 0.011