First published: Mon Nov 13 2017(Updated: )
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MISP | =2.4.82 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-16802 is classified as medium due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2017-16802, upgrade to MISP version 2.4.83 or later where the vulnerability is patched.
CVE-2017-16802 is an XSS vulnerability that allows for the execution of malicious scripts via manipulated organization names.
CVE-2017-16802 is found in MISP version 2.4.82.
CVE-2017-16802 can be exploited by an attacker adding a specially crafted organization name, leading to XSS when viewed by users.