First published: Tue Jan 19 2021(Updated: )
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | =2.4.136 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this MISP vulnerability is CVE-2021-25325.
The severity level of CVE-2021-25325 is medium (6.1).
CVE-2021-25325 affects MISP version 2.4.136.
The CWE ID associated with CVE-2021-25325 is CWE-79.
Yes, a fix is available for CVE-2021-25325. It can be found at https://github.com/MISP/MISP/commit/829c3199ba3afdecb52e0719509f3df4463be5b4.