CVE-2017-15216: XSS
Published Oct 10, 2017
·Updated
MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.
Affected Software
1 affected component
Misp-project Misp<=2.4.80
Event History
Oct 10, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15216?
The severity of CVE-2017-15216 is considered medium due to its potential for reflected XSS attacks.
2
How do I fix CVE-2017-15216?
To fix CVE-2017-15216, upgrade MISP to version 2.4.81 or later.
3
What does CVE-2017-15216 affect?
CVE-2017-15216 affects MISP versions up to and including 2.4.80.
4
What is the nature of the vulnerability in CVE-2017-15216?
CVE-2017-15216 is a reflected XSS vulnerability that occurs during the quickDelete action to delete a sighting.
5
Which components are involved in CVE-2017-15216?
CVE-2017-15216 involves the app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js components.