PT-2022-19683 · Misp · Misp

Dawid Czarnecki

·

Published

2022-04-20

·

Updated

2023-12-21

·

CVE-2022-29533

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.4.158
Description The issue is related to a Cross-Site Scripting (XSS) vulnerability in the app/Controller/OrganisationsController.php file, specifically in situations involving a "weird single checkbox page."
Recommendations For versions prior to 2.4.158, update to version 2.4.158 or later to resolve the issue. As a temporary workaround, consider restricting access to the OrganisationsController.php file until a patch is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-29533

Affected Products

Misp