vendor:
MISP
by:
Mücahit Çeri
4.1
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: MISP
Affected Version From: 2.4.0171
Affected Version To: 2.4.0171
Patch Exists: NO
Related CWE: CVE-2023-37307
CPE: a:misp_project:misp:2.4.171
Platforms Tested: Ubuntu 20.04
2023
MISP 2.4.171 Stored XSS Vulnerability
An authenticated user can inject malicious code into the 'Name' parameter while adding a cluster in MISP version 2.4.171, leading to the execution of arbitrary scripts in the context of the user's session. This vulnerability has been assigned CVE-2023-37307.
Mitigation:
To mitigate this vulnerability, users should sanitize and validate user input to prevent the execution of scripts. Regular security updates and patches from the vendor should be applied promptly.