CVE-2017-16802: XSS
Published Nov 13, 2017
·Updated
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
Affected Software
1 affected component
Misp-project Misp=2.4.82
Remediation
Event History
Nov 13, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16802?
The severity of CVE-2017-16802 is classified as medium due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-16802?
To fix CVE-2017-16802, upgrade to MISP version 2.4.83 or later where the vulnerability is patched.
3
What type of vulnerability is CVE-2017-16802?
CVE-2017-16802 is an XSS vulnerability that allows for the execution of malicious scripts via manipulated organization names.
4
In which software is CVE-2017-16802 found?
CVE-2017-16802 is found in MISP version 2.4.82.
5
How can CVE-2017-16802 be exploited?
CVE-2017-16802 can be exploited by an attacker adding a specially crafted organization name, leading to XSS when viewed by users.