MISP 在其双因素认证(TOTP)验证流程中存在一个漏洞,允许有效的一次性验证码在其基于时间的有效期内被多次接受。 该问题存在于用户登录流程中,其中 TOTP 代码作为第二认证因子进行验证。由于系统未记录某个特定的 TOTP 时间窗口是否已被使用过,同一验证码在其整个有效时间窗口内(通常为 30 秒)保持有效。攻击者如果在用户合法登录过程中截获了有效的验证码,可以重放该代码以冒充该用户认证第二个会话。 前提条件: 目标用户已启用基于 TOTP 的双因素认证。 攻击者能够观察或拦截用户在合法登录过程中输入的 TOT
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103651 | 7.6 HIGH | MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authenticatio |
| CVE-2026-103659 | 7.1 HIGH | MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attrib |
| CVE-2026-103858 | 5.3 MEDIUM | MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussio |
| CVE-2026-103662 | 5.1 MEDIUM | MISP Reflected XSS in Taxonomy Tag Confirmation Forms |
| CVE-2026-103664 | 4.8 MEDIUM | MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter |
No comments yet