CVE-2017-13671: XSS
Published Aug 24, 2017
·Updated
app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.
Affected Software
2 affected components
Misp Misp<=2.4.78
Misp-project Misp<=2.4.78
Remediation
Event History
Aug 24, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-13671?
CVE-2017-13671 is classified as a medium severity vulnerability due to its potential for persistent XSS attacks.
2
How do I fix CVE-2017-13671?
To fix CVE-2017-13671, upgrade MISP to version 2.4.79 or later.
3
Who is affected by CVE-2017-13671?
CVE-2017-13671 affects users of MISP versions prior to 2.4.79, specifically those utilizing the comment feature.
4
What type of vulnerability is CVE-2017-13671?
CVE-2017-13671 is a persistent cross-site scripting (XSS) vulnerability.
5
Can CVE-2017-13671 be exploited remotely?
CVE-2017-13671 cannot be exploited remotely; it only affects users sharing the same MISP instance.