PT-2026-96736 · Misp · Misp

·

CVE-2026-95682

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description A stored cross-site scripting (XSS) issue exists in the admin email composition screen. The organization name setting is interpolated directly into a JavaScript string literal using an unescaped PHP echo: var org = "<?php echo $org;?>";. Since the value is placed inside a double-quoted JavaScript string without encoding, an organization name containing a double-quote character or a backslash can terminate the string literal and inject arbitrary JavaScript. This script executes in the context of any authenticated user who loads the admin email page, which could lead to session hijacking, data exfiltration, or privileged actions. Exploitation requires the ability to modify the organization name and another authenticated user visiting the affected view.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95682

Affected Products

Misp