First published: Sat Dec 05 2020(Updated: )
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | =2.4.135 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29572 is a vulnerability in MISP 2.4.135 that allows cross-site scripting (XSS) attacks through the authkey comment field.
The severity of CVE-2020-29572 is medium, with a CVSS score of 6.1.
CVE-2020-29572 affects MISP version 2.4.135.
To fix CVE-2020-29572, update MISP to a version that includes the fix, such as 2.4.136 or later.
Yes, you can find more information about CVE-2020-29572 in the official GitHub commit: https://github.com/MISP/MISP/commit/0bfc0bf38a7758b27c5c446fec5e3b905e5a54ab