ZeroHour

CVE-2017-13671

CVSS 3.0
6.1 medium
EPSS
<1%p60
Published
()
Modified
Description

app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.

Vendors
misp-project
Products
misp
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.