We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-58129



Description

In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.

Reserved 2025-03-28 | Published 2025-03-28 | Updated 2025-03-31 | Assigner mitre


MEDIUM: 5.5CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

Any version before 2.4.193
affected

References

github.com/MISP/MISP/releases/tag/v2.4.193

github.com/...ommit/09a43870e733f79ffa33753ddc7bce3cbb5a5647

cve.org (CVE-2024-58129)

nvd.nist.gov (CVE-2024-58129)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-58129

Support options

Helpdesk Chat, Email, Knowledgebase