First published: Sun Dec 03 2023(Updated: )
app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.179 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-49926.
The severity of CVE-2023-49926 is medium with a CVSS score of 6.1.
CVE-2023-49926 affects MISP versions up to 2.4.179.
The CWE ID associated with CVE-2023-49926 is CWE-79.
To fix the XSS vulnerability in the event timeline widget, update MISP to version 2.4.179 or later.