CVE-2023-24026: XSS
Published Jan 20, 2023
·Updated
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
Affected Software
1 affected component
Misp-project Misp=2.4.167
Remediation
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24026?
The severity of CVE-2023-24026 is medium.
2
How does the XSS vulnerability in MISP 2.4.167 occur?
The XSS vulnerability in MISP 2.4.167 occurs through an event-graph preview payload in app/webroot/js/event-graph.js.
3
Which version of MISP is affected by CVE-2023-24026?
MISP version 2.4.167 is affected by CVE-2023-24026.
4
What is the Common Weakness Enumeration (CWE) number for CVE-2023-24026?
The Common Weakness Enumeration (CWE) number for CVE-2023-24026 is 79.
5
Is there a fix available for the XSS vulnerability in MISP 2.4.167?
A fix for the XSS vulnerability in MISP 2.4.167 is available in the commit a46f794a136001101cbec84fccf3cc824e983493 on GitHub.