First published: Wed May 08 2019(Updated: )
A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MISP | <2.4.107 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11812 is classified as a medium severity vulnerability due to its persistent cross-site scripting (XSS) nature.
To fix CVE-2019-11812, upgrade MISP to version 2.4.107 or later.
CVE-2019-11812 can facilitate persistent cross-site scripting (XSS) attacks, allowing attackers to include JavaScript in discussions.
MISP versions before 2.4.107 are affected by CVE-2019-11812.
The impact of CVE-2019-11812 on users includes potential hijacking of user sessions and unauthorized actions on the application.