CVE-2023-37307: XSS
In MISP before 2.4.172, titleforlayout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-37307?
CVE-2023-37307 refers to a vulnerability in MISP, specifically in versions before 2.4.172, where the title_for_layout parameter is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
What is the severity of CVE-2023-37307?
CVE-2023-37307 has a severity rating of 7.5 (High).
How does CVE-2023-37307 affect MISP?
CVE-2023-37307 affects MISP versions before 2.4.172, allowing potential attackers to exploit the title_for_layout parameter in Correlations, CorrelationExclusions, and Layouts.
How can I fix CVE-2023-37307?
To fix CVE-2023-37307, it is recommended to update MISP to version 2.4.172 or later where the vulnerability has been patched.
Where can I find more information about CVE-2023-37307?
More information about CVE-2023-37307 can be found at the following references: [GitHub Commit](https://github.com/MISP/MISP/commit/286c84fab0047726a6a396ceefaae1bb666fc485), [GitHub Comparison](https://github.com/MISP/MISP/compare/v2.4.171...v2.4.172), [Zigrin Advisories](https://zigrin.com/advisories/misp-stored-xss/)