First published: Wed Apr 20 2022(Updated: )
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.158 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29532 is a vulnerability in MISP version 2.4.158 and below that allows for a stored XSS attack if an administrator clicks on a javascript: URL in the URL field.
CVE-2022-29532 has a severity rating of medium with a CVSS score of 4.8.
CVE-2022-29532 affects MISP versions before 2.4.158 and can be exploited to perform a stored XSS attack.
Yes, the fix for CVE-2022-29532 is included in MISP version 2.4.158.
To protect your MISP installation from CVE-2022-29532, make sure to update to version 2.4.158 or later.