Security
Headlines
HeadlinesLatestCVEs

Headline

MISP 2.4.171 Cross Site Scripting

MISP version 2.4.171 suffers from a persistent cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#ubuntu#git#auth
# Exploit Title: MISP 2.4.171 Stored XSS [CVE-2023-37307] (Authenticated)# Date: 8th October 2023# Exploit Author: Mücahit Çeri# Vendor Homepage: https://www.circl.lu/# Software Link: https://github.com/MISP/MISP# Version: 2.4.171# Tested on: Ubuntu 20.04# CVE : CVE-2023-37307# Exploit:Logged in as low privileged account1)Click on the "Galaxies" button in the top menu2)Click "Add Cluster" in the left menu.3)Enter the payload "</title><script>alert(1)</script>" in the Name parameter.4)Other fields are filled randomly. Click on Submit button.5)When the relevant cluster is displayed, we see that alert(1) is running

Related news

CVE-2023-37307: fix: [layout:title] Make sure page title are correctly formatted · MISP/MISP@286c84f

In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

Packet Storm: Latest News

NIELD (Network Interface Events Logging Daemon) 0.6.2