PT-2026-103758 · Misp · Misp

·

CVE-2026-103662

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.48
Description Reflected cross-site scripting (XSS) exists in the legacy taxonomy tag management confirmation forms used for adding and disabling tags. The issue occurs because the application echoes a user-supplied tag name value from the request unescaped into the rendered HTML output. An authenticated site administrator who visits a crafted URL can have arbitrary JavaScript executed in their browser session, potentially leading to the theft of session tokens, CSRF tokens, or the performance of privileged actions within the interface.
Recommendations Update to version 2.5.48 or later. As a temporary mitigation, disable the legacy taxonomy tag confirmation views.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103662

Affected Products

Misp