CVE-2018-11562: XSS
Published May 30, 2018
·Updated
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.
Affected Software
2 affected components
Misp Misp=2.4.91
Misp-project Misp=2.4.91
Remediation
Event History
May 30, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-11562?
CVE-2018-11562 is considered a medium severity vulnerability due to its reflected XSS nature.
2
How do I fix CVE-2018-11562?
To fix CVE-2018-11562, upgrade MISP to a version later than 2.4.91, where the issue has been resolved.
3
What type of vulnerability is CVE-2018-11562?
CVE-2018-11562 is a reflected Cross-Site Scripting (XSS) vulnerability.
4
How does CVE-2018-11562 affect users?
CVE-2018-11562 affects users by potentially allowing attackers to execute malicious scripts in the context of the user’s browser session.
5
In which versions of MISP is CVE-2018-11562 present?
CVE-2018-11562 is present in MISP version 2.4.91.