Description
app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/100533
Patch, Third Party Advisory x_refsource_confirm
https://github.com/MISP/MISP/commit/6eba658d4a648b41b357025d864c19a67412b8aa
Scores
CVSS v3
6.1
EPSS
0.0023
EPSS Percentile
46.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
misp/misp
< 2.4.78
Published
Aug 24, 2017
Tracked Since
Feb 18, 2026