app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/MISP/MISP/commit/2989aa05225aa9b3a592ca50cbf8350ef256909c | third party advisory patch |
https://github.com/MISP/MISP/compare/v2.4.125...v2.4.126 | third party advisory release notes |