CVE-2021-3184: XSS
Published Jan 19, 2021
·Updated
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/globalmenu.ctp user homepage favourite button.
Affected Software
2 affected components
Misp Misp=2.4.136
Misp-project Misp=2.4.136
Remediation
Event History
Jan 19, 2021
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-3184?
CVE-2021-3184 is a vulnerability in MISP 2.4.136 that allows for cross-site scripting (XSS) attacks via a crafted URL.
2
How severe is CVE-2021-3184?
CVE-2021-3184 has a medium severity rating with a CVSS score of 6.1.
3
How does CVE-2021-3184 affect MISP?
CVE-2021-3184 affects MISP version 2.4.136.
4
How can the CVE-2021-3184 vulnerability be exploited?
The CVE-2021-3184 vulnerability can be exploited by an attacker by sending a specially crafted URL to the user homepage favourite button of the MISP application.
5
Is there a fix for CVE-2021-3184?
Yes, a fix for CVE-2021-3184 is available in the MISP version mentioned in the vulnerability description.