PT-2019-12503 · Misp · Misp

João Lucas Melo Brasio

·

Published

2019-05-08

·

Updated

2019-05-08

·

CVE-2019-11814

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.4.107
Description An issue was discovered in the MISP software, where there is a persistent XSS vulnerability via image names in titles. This issue can be demonstrated by a screenshot, indicating the potential for malicious code execution through crafted image names.
Recommendations For versions prior to 2.4.107, update to version 2.4.107 or later to resolve the issue. As a temporary workaround, consider restricting the ability to upload images with malicious names to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11814

Affected Products

Misp