CVE-2023-41098: XSS
Published Aug 23, 2023
·Updated
An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.
Affected Software
2 affected components
Misp Misp=2.4.174
Misp-project Misp=2.4.174
Remediation
Event History
Aug 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-41098.
2
What is the severity of CVE-2023-41098?
The severity of CVE-2023-41098 is medium with a severity value of 6.1.
3
How does the vulnerability manifest?
The vulnerability manifests as a reflected XSS issue in app/Controller/DashboardsController.php.
4
What is the affected software version?
The affected software version is MISP 2.4.174.
5
How can I fix CVE-2023-41098?
To fix CVE-2023-41098, update MISP to version 2.4.175 or later.