CVE-2021-25325: XSS
Published Jan 19, 2021
·Updated
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
Affected Software
2 affected components
Misp Misp=2.4.136
Misp-project Misp=2.4.136
Remediation
Event History
Jan 19, 2021
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this MISP vulnerability?
The vulnerability ID for this MISP vulnerability is CVE-2021-25325.
2
What is the severity level of CVE-2021-25325?
The severity level of CVE-2021-25325 is medium (6.1).
3
How does CVE-2021-25325 affect MISP?
CVE-2021-25325 affects MISP version 2.4.136.
4
What is the CWE ID associated with CVE-2021-25325?
The CWE ID associated with CVE-2021-25325 is CWE-79.
5
Is there a fix available for CVE-2021-25325?
Yes, a fix is available for CVE-2021-25325. It can be found at https://github.com/MISP/MISP/commit/829c3199ba3afdecb52e0719509f3df4463be5b4.