Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

David Andre

#45999of 57,416
6.3Total CVSS
Vulnerabilities · 1
PT-2026-96091
6.3
2026-09-21
Misp · Misp · CVE-2026-94373
**Name of the Vulnerable Software and Affected Versions** MISP versions prior to 2.5.47 **Description** A DOM-based cross-site scripting (XSS) issue exists in the contextual menu JavaScript component. The `ContextualMenu` class populates HTML `<option>` elements by assigning user-controllable values to the `innerHTML` property. Since `innerHTML` parses and renders HTML markup, untrusted strings supplied as the option text (`value.text` or `value`) are interpreted as live DOM content instead of plain text. This allows an attacker to inject arbitrary HTML or JavaScript that executes in the victim's browser within the application origin, potentially leading to session hijacking, data exfiltration, or unauthorized actions. **Recommendations** Update to version 2.5.47 or later.