First published: Wed Apr 20 2022(Updated: )
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.158 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29530 is an issue discovered in MISP before version 2.4.158, which allows for stored XSS (Cross-Site Scripting) attacks in the galaxy clusters.
CVE-2022-29530 has a severity rating of medium, with a CVSS score of 5.4.
The affected software for CVE-2022-29530 is MISP, versions up to and excluding 2.4.158.
To fix CVE-2022-29530, update MISP to version 2.4.158 or newer.
You can find more information about CVE-2022-29530 in the provided references: [Link 1](https://github.com/MISP/MISP/commit/107e271d78c255d658ce998285fe6f6c4f291b41), [Link 2](https://github.com/MISP/MISP/compare/v2.4.157...v2.4.158), [Link 3](https://zigrin.com/cakephp-application-cybersecurity-research-protect-your-website-from-stored-xss-attacks-understanding-and-preventing-vulnerabilities-in-open-source-applications/).