First published: Fri Jan 20 2023(Updated: )
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp-project Misp | =2.4.167 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24026 is medium.
The XSS vulnerability in MISP 2.4.167 occurs through an event-graph preview payload in app/webroot/js/event-graph.js.
MISP version 2.4.167 is affected by CVE-2023-24026.
The Common Weakness Enumeration (CWE) number for CVE-2023-24026 is 79.
A fix for the XSS vulnerability in MISP 2.4.167 is available in the commit a46f794a136001101cbec84fccf3cc824e983493 on GitHub.