CVE-2020-24085: XSS
Published Jan 20, 2021
·Updated
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code.
Affected Software
2 affected components
Misp Misp=2.4.128
Misp-project Misp=2.4.128
Remediation
Event History
Jan 20, 2021
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
Description
Jan 26, 2021
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-24085?
CVE-2020-24085 is a cross-site scripting (XSS) vulnerability that exists in MISP v2.4.128.
2
How severe is CVE-2020-24085?
CVE-2020-24085 has a severity level of medium with a CVSS score of 6.1.
3
How does CVE-2020-24085 work?
CVE-2020-24085 allows an attacker to execute malicious JavaScript code by exploiting a lack of controller validation in the "path" parameter in MISP v2.4.128.
4
What software versions are affected by CVE-2020-24085?
CVE-2020-24085 affects MISP v2.4.128.
5
How can CVE-2020-24085 be fixed?
To fix CVE-2020-24085, it is recommended to update to a patched version of MISP, such as the version mentioned in the reference link.