CVE-2023-28884: XSS
Published Mar 27, 2023
·Updated
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
Affected Software
2 affected components
Misp-project Malware Information Sharing Platform=2.4.169
Misp-project Misp=2.4.169
Remediation
Event History
Mar 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-28884.
2
What is the title of this vulnerability?
The title of this vulnerability is 'In MISP 2.4.169 app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.'
3
What is the severity of CVE-2023-28884?
The severity of CVE-2023-28884 is medium (6.1).
4
How does CVE-2023-28884 affect MISP?
CVE-2023-28884 affects MISP version 2.4.169.
5
How can I fix CVE-2023-28884?
To fix CVE-2023-28884, update MISP to a version that includes the fix mentioned in the references.