PT-2026-38424 · Misp · Misp
Bjørn Helseth
+1
·
Published
2026-05-07
·
Updated
2026-05-07
·
CVE-2026-8080
CVSS v4.0
6.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Green |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.37
Description
A stored cross-site scripting issue exists in the template element attribute handling logic. The application fails to validate arbitrary values for the
TemplateElementAttribute type and category fields against known attribute type and category definitions. This allows an attacker with permissions to create or modify template element attributes to store a crafted type value. This issue specifically affects the old templating engine, which is no longer accessible in version 2.5.37 and is scheduled for removal in version 2.5.38.Recommendations
Update to version 2.5.37 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp