First published: Thu Nov 19 2020(Updated: )
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | =2.4.134 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-28947 is medium (6.1).
CVE-2020-28947 affects MISP version 2.4.134.
The CWE for CVE-2020-28947 is CWE-79.
Yes, a fix is available for CVE-2020-28947. Please refer to the provided reference for more information.
You can find more information about CVE-2020-28947 at the provided reference: https://github.com/MISP/MISP/commit/626ca544ffb5604ea01bb291f69811668b6b5631