PT-2021-11003 · Misp · Misp

Diego Jurado Pallares

+1

·

Published

2021-01-20

·

Updated

2021-01-30

·

CVE-2020-24085

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: MISP version 2.4.128
Description: A cross-site scripting (XSS) issue exists due to a lack of validation in the path parameter, allowing an attacker to execute malicious JavaScript code. This occurs in the SetHomePage() function within the UserSettingsController.php file.
Recommendations: For MISP version 2.4.128, consider validating the path parameter to prevent malicious input, and restrict the execution of JavaScript code in the SetHomePage() function until a proper fix is applied. As a temporary workaround, restrict access to the UserSettingsController.php file to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24085

Affected Products

Misp