In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using only the event ID as the lookup condition, without applying the report's own distribution/ACL constraint
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-95806 | 7.7 HIGH | MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influe |
| CVE-2026-95658 | 6.9 MEDIUM | MISP CSRF vulnerability in workflow moduleStatelessExecution allows cross-site execution o |
| CVE-2026-95754 | 6.9 MEDIUM | MISP: Disabled-user check ineffective in pre-authentication TOTP login branch |
| CVE-2026-95667 | 6.9 MEDIUM | MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Credentials |
| CVE-2026-95679 | 6.9 MEDIUM | MISP Unauthenticated Blind SSRF via XML Body Processing |
| CVE-2026-95693 | 5.3 MEDIUM | MISP Information Disclosure via Forged Upload Path |
| CVE-2026-95805 | 5.3 MEDIUM | MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restric |
| CVE-2026-95698 | 5.3 MEDIUM | MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name |
| CVE-2026-95671 | 5.3 MEDIUM | MISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collecti |
| CVE-2026-95685 | 5.3 MEDIUM | MISP Missing Authorization on replaceSuggestionInReport Event Report Action |
| CVE-2026-95674 | 5.3 MEDIUM | MISP EventsController queryEnrichment allows querying unavailable or legacy modules withou |
| CVE-2026-95697 | 5.3 MEDIUM | MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Me |
| CVE-2026-95661 | 5.1 MEDIUM | MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type |
| CVE-2026-95665 | 5.1 MEDIUM | MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSON |
| CVE-2026-95703 | 5.1 MEDIUM | MISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_na |
| CVE-2026-95701 | 5.1 MEDIUM | MISP Path Traversal via Organization Name in Org-Statistics Logo Check |
| CVE-2026-95659 | 4.8 MEDIUM | MISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind Thread |
| CVE-2026-95682 | 4.8 MEDIUM | MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View |
暂无评论