In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/MISP/MISP/commit/b94c7978e5e6b1db369abeedbbf00bca975b08b7 | patch |
https://zigrin.com/advisories/misp-dom-based-xss/ | third party advisory |