CVE-2024-58129

In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

History

08 Jul 2025, 17:30

Type Values Removed Values Added
References () https://github.com/MISP/MISP/commit/09a43870e733f79ffa33753ddc7bce3cbb5a5647 - () https://github.com/MISP/MISP/commit/09a43870e733f79ffa33753ddc7bce3cbb5a5647 - Patch
References () https://github.com/MISP/MISP/releases/tag/v2.4.193 - () https://github.com/MISP/MISP/releases/tag/v2.4.193 - Release Notes
CPE cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
First Time Misp
Misp misp

01 Apr 2025, 20:26

Type Values Removed Values Added
Summary
  • (es) En MISP anterior a 2.4.193, los parámetros menu_custom_right_link_html se pueden configurar a través de la interfaz de usuario (es decir, sin utilizar la CLI) y, por lo tanto, los atacantes con privilegios de administrador pueden realizar ataques XSS contra cada página.

28 Mar 2025, 23:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

28 Mar 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 22:15

Updated : 2025-07-08 17:30


NVD link : CVE-2024-58129

Mitre link : CVE-2024-58129

CVE.ORG link : CVE-2024-58129


JSON object : View

Products Affected

misp

  • misp
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')