app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/MISP/MISP/commit/01521d614cb578de75a406394b4f0426f6036ba7 | third party advisory patch |
https://github.com/MISP/MISP/compare/v2.4.145...v2.4.146 | third party advisory patch |