First published: Fri Jun 30 2023(Updated: )
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp-project Malware Information Sharing Platform | <2.4.172 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37307 refers to a vulnerability in MISP, specifically in versions before 2.4.172, where the title_for_layout parameter is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
CVE-2023-37307 has a severity rating of 7.5 (High).
CVE-2023-37307 affects MISP versions before 2.4.172, allowing potential attackers to exploit the title_for_layout parameter in Correlations, CorrelationExclusions, and Layouts.
To fix CVE-2023-37307, it is recommended to update MISP to version 2.4.172 or later where the vulnerability has been patched.
More information about CVE-2023-37307 can be found at the following references: [GitHub Commit](https://github.com/MISP/MISP/commit/286c84fab0047726a6a396ceefaae1bb666fc485), [GitHub Comparison](https://github.com/MISP/MISP/compare/v2.4.171...v2.4.172), [Zigrin Advisories](https://zigrin.com/advisories/misp-stored-xss/)