CVE-2022-47928: XSS
Published Dec 22, 2022
·Updated
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/uploadfile.ctp.
Affected Software
2 affected components
Misp-project Malware Information Sharing Platform<2.4.167
Misp-project Misp<2.4.167
Remediation
Event History
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-47928?
The severity of CVE-2022-47928 is medium with a CVSS score of 6.1.
2
What is the impact of CVE-2022-47928?
CVE-2022-47928 allows an attacker to execute arbitrary code or scripts in the victim's browser, potentially leading to account compromise, data theft, or further attacks.
3
How can I fix CVE-2022-47928?
To fix CVE-2022-47928, upgrade to MISP version 2.4.167 or later.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-47928?
The Common Weakness Enumeration (CWE) ID for CVE-2022-47928 is CWE-79.
5
Where can I find more information about CVE-2022-47928?
You can find more information about CVE-2022-47928 and its fix in the following [GitHub commit](https://github.com/MISP/MISP/commit/684d3e51398d4ea032b06fa4a1cd2bdf7d8b0ede).