CVE-2018-11245

app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:misp-project:misp:2.4.91:*:*:*:*:*:*:*

History

21 Nov 2024, 03:42

Type Values Removed Values Added
References () https://github.com/MISP/MISP/commit/5efc07b12f82301a6086fd3433fedd69fe7119d3 - Patch, Third Party Advisory () https://github.com/MISP/MISP/commit/5efc07b12f82301a6086fd3433fedd69fe7119d3 - Patch, Third Party Advisory
References () https://zigrin.com/advisories/misp-xss-with-cortex-type-attributes/ - () https://zigrin.com/advisories/misp-xss-with-cortex-type-attributes/ -

28 Sep 2023, 14:15

Type Values Removed Values Added
References
  • (MISC) https://zigrin.com/advisories/misp-xss-with-cortex-type-attributes/ -

Information

Published : 2018-05-18 18:29

Updated : 2024-11-21 03:42


NVD link : CVE-2018-11245

Mitre link : CVE-2018-11245

CVE.ORG link : CVE-2018-11245


JSON object : View

Products Affected

misp-project

  • misp
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')