以下是该漏洞描述的专业中文翻译: MISP 事件模板处理中存在一个漏洞,允许具有创建或修改事件模板权限的认证用户绕过模板定义字段的验证。 方法仅在提供的定义已表示为数组时执行语义验证。如果调用者提供的是预编码的字符串(包括格式错误的 JSON 或表示意外数据类型的 JSON),该值就会绕过 ,只需满足通用的 验证规则即可。因此,无效的事件模板定义会被持久化存储在数据库中。 当事件模板随后被检索时, 尝试使用 解码存储的定义,但未处理解码失败的情况。因此,包含无效 JSON 的定义可能在检索过程中触发异常。由于事件模
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85216 | 9.5 CRITICAL | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials |
| CVE-2026-85236 | 8.8 HIGH | MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request |
| CVE-2026-85237 | 8.6 HIGH | Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass |
| CVE-2026-85221 | 7.6 HIGH | MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attack |
| CVE-2026-85238 | 7.6 HIGH | Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking |
| CVE-2026-85227 | 6.1 MEDIUM | Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAtta |
| CVE-2026-85226 | 5.3 MEDIUM | MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Co |
| CVE-2026-85230 | 5.3 MEDIUM | MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection |
No comments yet