PT-2026-96723 · Misp · Misp
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
A reflected cross-site scripting (XSS) issue exists in the event REST search export confirmation form. The view template
app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID list into a single-quoted JavaScript string literal using PHP's json encode() function without hex-encoding flags. Since json encode() does not escape single quotes by default, an attacker can inject a single-quote character to terminate the string and execute arbitrary JavaScript in the browser session of an authenticated user who navigates to a crafted URL. This affects the Default and UiBeta themes. Successful exploitation can lead to session hijacking, unauthorized actions, or exfiltration of sensitive session data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp