PT-2026-103758 · Misp · Misp
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.48
Description
Reflected cross-site scripting (XSS) exists in the legacy taxonomy tag management confirmation forms used for adding and disabling tags. The issue occurs because the application echoes a user-supplied tag name value from the request unescaped into the rendered HTML output. An authenticated site administrator who visits a crafted URL can have arbitrary JavaScript executed in their browser session, potentially leading to the theft of session tokens, CSRF tokens, or the performance of privileged actions within the interface.
Recommendations
Update to version 2.5.48 or later.
As a temporary mitigation, disable the legacy taxonomy tag confirmation views.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp