In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/MISP/MISP/commit/586cca384be6710b03e14bcbeb7588c1772604ec | third party advisory patch |
https://github.com/MISP/MISP/compare/f493659...0e4f66e | third party advisory patch |