CVE-2023-40224: XSS
Published Aug 10, 2023
·Updated
MISP 2.4.174 allows XSS in app/View/Events/index.ctp.
Other sources
MISP 2.4174 allows XSS in app/View/Events/index.ctp.
Affected Software
2 affected components
Misp Misp=2.4.174
Misp-project Misp=2.4.174
Remediation
Event History
Aug 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-40224?
CVE-2023-40224 is a vulnerability in MISP 2.4174 that allows XSS in app/View/Events/index.ctp.
2
What software versions are affected by CVE-2023-40224?
CVE-2023-40224 affects MISP version 2.4.174 specifically.
3
What is the severity of CVE-2023-40224?
CVE-2023-40224 has a severity level of medium with a CVSS score of 6.1.
4
How can I fix CVE-2023-40224?
To fix CVE-2023-40224, you should update MISP to a version that includes the fix, such as version 2.4175 or higher.
5
Where can I find more information about CVE-2023-40224?
More information about CVE-2023-40224 can be found in the official GitHub commit: https://github.com/MISP/MISP/commit/0274f8b6332e82317c9529b583d03897adf5883e