PT-2026-96091 · Misp · Misp

·

CVE-2026-94373

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.47
Description A DOM-based cross-site scripting (XSS) issue exists in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values to the innerHTML property. Since innerHTML parses and renders HTML markup, untrusted strings supplied as the option text (value.text or value) are interpreted as live DOM content instead of plain text. This allows an attacker to inject arbitrary HTML or JavaScript that executes in the victim's browser within the application origin, potentially leading to session hijacking, data exfiltration, or unauthorized actions.
Recommendations Update to version 2.5.47 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94373

Affected Products

Misp