Vulnerabilities (CVE)

Filtered by vendor Misp-project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48655 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
CVE-2023-48658 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
CVE-2023-48656 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
CVE-2023-48657 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
CVE-2023-48659 1 Misp-project 1 Malware Information Sharing Platform 2024-01-10 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
CVE-2015-5721 1 Misp-project 1 Malware Information Sharing Platform 2016-11-28 7.5 HIGH 9.8 CRITICAL
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.
CVE-2015-5719 1 Misp-project 1 Malware Information Sharing Platform 2016-11-28 10.0 HIGH 9.8 CRITICAL
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.