First published: Wed Apr 20 2022(Updated: )
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.158 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29529 is a vulnerability discovered in MISP before version 2.4.158 that allows for stored cross-site scripting (XSS) attacks via the LinOTP login field.
CVE-2022-29529 has a severity rating of medium with a CVSS score of 5.4.
CVE-2022-29529 affects MISP versions up to, but excluding, 2.4.158.
To fix CVE-2022-29529, it is recommended to update MISP to version 2.4.158 or later.
The CWE ID for CVE-2022-29529 is CWE-79, which corresponds to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').