PT-2026-96736 · Misp · Misp
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
A stored cross-site scripting (XSS) issue exists in the admin email composition screen. The organization name setting is interpolated directly into a JavaScript string literal using an unescaped PHP echo:
var org = "<?php echo $org;?>";. Since the value is placed inside a double-quoted JavaScript string without encoding, an organization name containing a double-quote character or a backslash can terminate the string literal and inject arbitrary JavaScript. This script executes in the context of any authenticated user who loads the admin email page, which could lead to session hijacking, data exfiltration, or privileged actions. Exploitation requires the ability to modify the organization name and another authenticated user visiting the affected view.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp