We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-58130



Description

In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.

Reserved 2025-03-28 | Published 2025-03-28 | Updated 2025-03-31 | Assigner mitre


HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

Any version before 2.4.193
affected

References

github.com/MISP/MISP/releases/tag/v2.4.193

github.com/...ommit/f08a2eaec25f0212c22b225c0b654bd60d089ef9

cve.org (CVE-2024-58130)

nvd.nist.gov (CVE-2024-58130)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-58130

Support options

Helpdesk Chat, Email, Knowledgebase