First published: Mon Jan 23 2023(Updated: )
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp-project Malware Information Sharing Platform | <=2.4.167 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-24070.
The severity of CVE-2023-24070 is medium with a CVSS score of 6.1.
The affected software is MISP version up to and including 2.4.167.
The CWE ID associated with CVE-2023-24070 is CWE-79.
To fix the XSS vulnerability in MISP, you should update to a version that includes the fix, such as version 2.4.168 or later.