First published: Mon Nov 13 2017(Updated: )
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp-project Misp | =2.4.82 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.