PT-2026-96065 · Misp · Misp
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.47
Description
The galaxy matrix statistics view (app/View/Users/statistics galaxymatrix.ctp) renders the galaxy name directly into HTML output using the
sprintf() function without proper HTML encoding. An authenticated user with the perm galaxy editor permission can create or modify a galaxy name containing arbitrary HTML or JavaScript. When other users access the galaxy matrix statistics page, the embedded script executes in their browser context, potentially leading to session hijacking, credential theft, data exfiltration, or unauthorized actions within the application.Recommendations
Update MISP to version 2.5.47 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp