CVE-2023-24070: XSS
Published Jan 23, 2023
·Updated
app/View/AuthKeys/authkeydisplay.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
Affected Software
2 affected components
Misp-project Malware Information Sharing Platform<=2.4.167
Misp-project Misp<=2.4.167
Remediation
Event History
Jan 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-24070.
2
What is the severity of CVE-2023-24070?
The severity of CVE-2023-24070 is medium with a CVSS score of 6.1.
3
What is the affected software?
The affected software is MISP version up to and including 2.4.167.
4
What is the CWE ID associated with CVE-2023-24070?
The CWE ID associated with CVE-2023-24070 is CWE-79.
5
How can I fix the XSS vulnerability in MISP?
To fix the XSS vulnerability in MISP, you should update to a version that includes the fix, such as version 2.4.168 or later.