CVE-2020-28947: XSS
Published Nov 19, 2020
·Updated
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
Affected Software
2 affected components
Misp Misp=2.4.134
Misp-project Misp=2.4.134
Remediation
Event History
Nov 19, 2020
CVE Published
via MITRE·05:44 PM
Data Sourced
via MITRE·05:44 PM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-28947?
The severity of CVE-2020-28947 is medium (6.1).
2
How does CVE-2020-28947 affect MISP?
CVE-2020-28947 affects MISP version 2.4.134.
3
What is the CWE for CVE-2020-28947?
The CWE for CVE-2020-28947 is CWE-79.
4
Is there a fix available for CVE-2020-28947?
Yes, a fix is available for CVE-2020-28947. Please refer to the provided reference for more information.
5
Where can I find more information about CVE-2020-28947?
You can find more information about CVE-2020-28947 at the provided reference: https://github.com/MISP/MISP/commit/626ca544ffb5604ea01bb291f69811668b6b5631