A vulnerability, which was classified as problematic, has been found in MISP 2.4.147. This issue affects an unknown functionality of the file app/View/GalaxyElements/ajax/index.ctp of the component Galaxy Cluster Element Handler. Applying a patch is able to eliminate this problem. The bugfix is ready for download at github.com.
MISP 2.4.147 Galaxy Cluster Element index.ctp cross site scripting
- Virtual Patching
- July 31, 2021
- 10:05 pm
CVE-2024-8762 : CODE-PROJECTS CRUD OPERATION SYSTEM 1.0 /UPDATEDATA.PHP SID SQL INJECTION
Description A vulnerability was found in code-projects Crud Operation System 1.0. It has been classified as critical. This affects an
CVE-2024-34334 : ORDAT FOSS-ONLINE UP TO 2.24.00 FORGOT PASSWORD SQL INJECTION
Description ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function. References https://mind-bytes.de/sql-injection-in-foss-online-cve-2024-34334/
CVE-2024-45383 : MICROSOFT HIGH DEFINITION AUDIO BUS DRIVER 10.0.19041.3636 IRP HDAUDBUS_DMA RESOURCE CONTROL
Description A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636