CVE-2021-37743: XSS
Published Jul 30, 2021
·Updated
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
Affected Software
2 affected components
Misp Misp=2.4.147
Misp-project Misp=2.4.147
Remediation
Event History
Jul 30, 2021
CVE Published
via MITRE·02:09 AM
Data Sourced
via MITRE·02:09 AM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37743?
CVE-2021-37743 is a vulnerability in MISP 2.4.147 that allows Stored XSS when viewing galaxy cluster elements in JSON format.
2
What is the severity of CVE-2021-37743?
CVE-2021-37743 has a severity keyword of medium and a severity value of 5.4.
3
How does CVE-2021-37743 affect MISP?
CVE-2021-37743 affects MISP version 2.4.147.
4
How can I fix CVE-2021-37743?
To fix CVE-2021-37743, update MISP to a version that includes the fix, such as MISP version 2.4.148 or later.
5
Where can I find more information about CVE-2021-37743?
More information about CVE-2021-37743 can be found at the following reference: [GitHub Commit](https://github.com/MISP/MISP/commit/f318f7c0ddac7dfd2b1f246fd8f488d9dfc3a4bf).