Impact
MISP, a security information and event management platform, contains a reflected cross‑site scripting vulnerability in the legacy taxonomy tag confirmation forms (add tag and disable tag). The confirmation forms echo a user‑supplied tag name value from the request without escaping it into the rendered HTML, allowing an attacker to craft a URL that, when an authenticated site administrator visits, executes arbitrary JavaScript in the administrator’s browser. This could lead to theft of session tokens, CSRF tokens, or other sensitive data and enable the attacker to perform privileged actions within the MISP interface.
Affected Systems
The vulnerability affects MISP instances running any version earlier than 2.5.48, provided the legacy taxonomy tag confirmation views are enabled. It requires an authenticated site administrator to follow a crafted link.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the vulnerability is not listed in CISA KEV, with no EPSS score available. Exploitation requires an attacker to generate a malicious URL and entice an authenticated administrator to open it, typically through phishing. The attack vector is reflected and confined to the victim’s browser; the privilege escalation is limited to the administrator’s session within the web application, but credential theft and privilege abuse remain significant concerns.
OpenCVE Enrichment