First published: Thu Mar 28 2019(Updated: )
In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MISP | <2.4.105 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10254 is considered a medium severity vulnerability due to its potential for exploitation leading to reflected Cross-Site Scripting (XSS).
To fix CVE-2019-10254, upgrade MISP to version 2.4.105 or later to eliminate the reflected XSS vulnerability.
CVE-2019-10254 is a reflected Cross-Site Scripting (XSS) vulnerability found in MISP applications before version 2.4.105.
CVE-2019-10254 is present in MISP versions prior to 2.4.105.
By exploiting CVE-2019-10254, attackers can execute malicious scripts in the context of the user's browser, potentially stealing session cookies or sensitive information.