CVE-2021-37534: XSS
Published Jul 26, 2021
·Updated
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
Affected Software
2 affected components
Misp Misp=2.4.146
Misp-project Misp=2.4.146
Remediation
Event History
Jul 26, 2021
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-37534.
2
What is the severity of CVE-2021-37534?
The severity of CVE-2021-37534 is medium with a CVSS score of 5.4.
3
What is the affected version of the software?
The affected version of the software is MISP 2.4.146.
4
How does CVE-2021-37534 occur?
CVE-2021-37534 occurs when forking a galaxy cluster in MISP 2.4.146.
5
Is there a fix available for CVE-2021-37534?
Yes, a fix is available. Please refer to the official GitHub commit: https://github.com/MISP/MISP/commit/78edbbca64a1edc4390560cc106d0d418064355d