PT-2026-96091 · Misp · Misp
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.47
Description
A DOM-based cross-site scripting (XSS) issue exists in the contextual menu JavaScript component. The
ContextualMenu class populates HTML <option> elements by assigning user-controllable values to the innerHTML property. Since innerHTML parses and renders HTML markup, untrusted strings supplied as the option text (value.text or value) are interpreted as live DOM content instead of plain text. This allows an attacker to inject arbitrary HTML or JavaScript that executes in the victim's browser within the application origin, potentially leading to session hijacking, data exfiltration, or unauthorized actions.Recommendations
Update to version 2.5.47 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp