CVE-2023-24027: XSS
Published Jan 20, 2023
·Updated
In MISP 2.4.167, app/webroot/js/actiontable.js allows XSS via a network history name.
Affected Software
2 affected components
Misp Misp=2.4.167
Misp-project Misp=2.4.167
Remediation
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-24027.
2
What is the title of this vulnerability?
The title of this vulnerability is 'In MISP 2.4.167 app/webroot/js/action_table.js allows XSS via a network history name.'
3
What is the severity of CVE-2023-24027?
The severity of CVE-2023-24027 is medium.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by injecting malicious code into a network history name in MISP 2.4.167.
5
Is there a fix available for CVE-2023-24027?
Yes, a fix is available for CVE-2023-24027. It can be found in the official GitHub repository of MISP.