First published: Thu Dec 22 2022(Updated: )
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp-project Malware Information Sharing Platform | <2.4.167 | |
<2.4.167 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-47928 is medium with a CVSS score of 6.1.
CVE-2022-47928 allows an attacker to execute arbitrary code or scripts in the victim's browser, potentially leading to account compromise, data theft, or further attacks.
To fix CVE-2022-47928, upgrade to MISP version 2.4.167 or later.
The Common Weakness Enumeration (CWE) ID for CVE-2022-47928 is CWE-79.
You can find more information about CVE-2022-47928 and its fix in the following [GitHub commit](https://github.com/MISP/MISP/commit/684d3e51398d4ea032b06fa4a1cd2bdf7d8b0ede).