CVE-2024-54674: XSS
Published Dec 4, 2024
·Updated
app/View/GalaxyClusters/clusterexportmispgalaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom clusters into the misp-galaxy format.
Affected Software
1 affected component
Misp Misp<2.5.2
Event History
Dec 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-54674?
CVE-2024-54674 has been classified as a high severity vulnerability due to the stored cross-site scripting (XSS) it introduces.
2
How do I fix CVE-2024-54674?
To fix CVE-2024-54674, upgrade your MISP installation to version 2.5.3 or later where the vulnerability has been patched.
3
What type of vulnerability is CVE-2024-54674?
CVE-2024-54674 is a stored XSS vulnerability that affects the export functionality of custom clusters in MISP.
4
In which version of MISP is CVE-2024-54674 present?
CVE-2024-54674 is present in MISP version 2.5.2 and earlier.
5
What impact does CVE-2024-54674 have on MISP users?
CVE-2024-54674 may allow attackers to inject malicious scripts, potentially leading to session hijacking or unauthorized actions by users exporting custom clusters.