Impact
A reflected XSS flaw exists in MISP’s analyst data notes panel: the seed path parameter supplied in the URL is injected directly into inline JavaScript without sanitization or type validation. When an authenticated user opens a maliciously crafted link, the embedded script runs in the victim’s browser context, allowing an attacker to read session information, capture sensitive data displayed on the page, or perform actions as the user. The vulnerability is a classic example of CWE‑79 – Cross‑Site Scripting.
Affected Systems
MISP installations running versions prior to the fix revision 58925dbf0, which corresponds to releases before v2.5.48, are vulnerable. The issue is tied to the MISP product.
Risk and Exploitability
The CVSS score of 4.8 places the issue in the medium‑risk range, and there is no EPSS data available, meaning the current exploit probability is unknown. The vulnerability is not listed in CISA’s KEV catalog, but it can be triggered via a simple phishing link that convinces an authenticated user to visit a crafted URL. Once the victim opens the link, the exploit is executed immediately within the browser, providing the attacker with the ability to harvest session tokens or inject malicious content.
OpenCVE Enrichment