PT-2026-96721 · Misp · Misp
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.47
Description
A reflected cross-site scripting (XSS) issue exists in the
AnalystDataController::viewForObject action. The method accepts a parent object type parameter from the URL without validation and passes it to the Overmind-themed AnalystData thread view element. This value is then interpolated into translated strings and rendered in the HTML response without output encoding. An authenticated attacker can induce a victim to visit a crafted URL to execute arbitrary JavaScript in the victim's browser within the application context, potentially allowing the attacker to read session data, manipulate the page, or perform actions on behalf of the victim. The affected components are the AnalystData controller and the Overmind theme's AnalystData thread element.Recommendations
Update to version 2.5.47 or later.
Fix
Improper Encoding or Escaping of Output
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Misp