First published: Fri Mar 23 2018(Updated: )
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp-project Misp | <2.4.89 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8948 is a vulnerability in MISP before version 2.4.89 that allows attackers to execute cross-site scripting (XSS) attacks via a malicious MISP module.
CVE-2018-8948 has a severity level of medium, with a CVSS score of 6.1.
CVE-2018-8948 affects MISP versions before 2.4.89.
The CWE for CVE-2018-8948 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability.
Yes, the vulnerability has been fixed in MISP version 2.4.89. It is recommended to update to the latest version to mitigate the issue.