MISP 仪表盘的 ButtonWidget 配置中存在一个持久化的不安全 URL 注入漏洞。仪表盘组件的 URL 仅在组件渲染时进行验证,而在配置保存时未做验证。因此,能够修改仪表盘组件设置的经过身份验证的用户可以通过任意一种设置持久化路径,将任意 URL 值(包括使用 方案的 URL)持久化存储。 存储在仪表盘按钮中的恶意 URL,如果该值在到达渲染或导航路径时未经过现有的运行时验证,则可能在 MISP 的安全上下文中导致客户端脚本执行。这种执行可能允许攻击者以受影响用户的权限执行操作,或访问其 MISP 会话
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85216 | 9.5 CRITICAL | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials |
| CVE-2026-85236 | 8.8 HIGH | MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request |
| CVE-2026-85237 | 8.6 HIGH | Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass |
| CVE-2026-85221 | 7.6 HIGH | MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attack |
| CVE-2026-85238 | 7.6 HIGH | Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking |
| CVE-2026-85239 | 7.1 HIGH | MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service |
| CVE-2026-85227 | 6.1 MEDIUM | Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAtta |
| CVE-2026-85226 | 5.3 MEDIUM | MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Co |
No comments yet