CVE-2024-54675: XSS
Published Dec 4, 2024
·Updated
app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow.
Affected Software
1 affected component
Misp Misp<2.5.2
Event History
Dec 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-54675?
CVE-2024-54675 is classified as a stored XSS vulnerability affecting MISP versions up to 2.5.2.
2
How do I fix CVE-2024-54675?
To mitigate CVE-2024-54675, it is recommended to upgrade to MISP version 2.5.3 or later.
3
What impact does CVE-2024-54675 have on MISP?
CVE-2024-54675 allows attackers to inject malicious scripts into the workflows editor, potentially compromising user accounts or data.
4
Is CVE-2024-54675 a zero-day vulnerability?
CVE-2024-54675 is not categorized as a zero-day vulnerability since it has been publicly disclosed and a patch is available.
5
Which versions of MISP are affected by CVE-2024-54675?
CVE-2024-54675 affects MISP versions prior to 2.5.3.