First published: Wed Dec 04 2024(Updated: )
app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MISP | <2.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54675 is classified as a stored XSS vulnerability affecting MISP versions up to 2.5.2.
To mitigate CVE-2024-54675, it is recommended to upgrade to MISP version 2.5.3 or later.
CVE-2024-54675 allows attackers to inject malicious scripts into the workflows editor, potentially compromising user accounts or data.
CVE-2024-54675 is not categorized as a zero-day vulnerability since it has been publicly disclosed and a patch is available.
CVE-2024-54675 affects MISP versions prior to 2.5.3.