PT-2026-46226 · Misp · Misp
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
A URL validation flaw in the dashboard button widget allows a crafted relative-looking URL to be accepted as a local path while browsers interpret it as an external URL. The validation process rejects URLs with explicit schemes, hosts, or user components, but fails to reject paths starting with a slash followed by a backslash (e.g.,
/example.com). Because some browsers normalize backslashes as forward slashes, this can result in a scheme-relative external navigation target. Furthermore, the generated href concatenates the reconstructed URL with the original URL, which may lead to unsafe or malformed link generation. An attacker capable of configuring or influencing a dashboard button URL could create a button that appears to point internally but redirects users to an attacker-controlled site, facilitating phishing, credential theft, or social engineering.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp