PT-2026-96065 · Misp · Misp

·

CVE-2026-94277

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.47
Description The galaxy matrix statistics view (app/View/Users/statistics galaxymatrix.ctp) renders the galaxy name directly into HTML output using the sprintf() function without proper HTML encoding. An authenticated user with the perm galaxy editor permission can create or modify a galaxy name containing arbitrary HTML or JavaScript. When other users access the galaxy matrix statistics page, the embedded script executes in their browser context, potentially leading to session hijacking, credential theft, data exfiltration, or unauthorized actions within the application.
Recommendations Update MISP to version 2.5.47 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94277

Affected Products

Misp