Impact
The vulnerability is a stored cross‑site scripting flaw in the remote event preview index of MISP. The count field value is rendered without HTML encoding, allowing an attacker who can create or modify events on a linked server to embed script or markup. When a local user views the preview, the unescaped value is executed in the browser, leading to arbitrary JavaScript execution in the victim’s session.
Affected Systems
Affected vendors and products are MISP from the MISP project. Versions before 2.5.48 are vulnerable. The flaw occurs only when a linked or remote MISP server is configured and the local instance renders the remote event preview index.
Risk and Exploitability
The CVSS score of 5.3 marks the flaw as moderate but not critical. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Exploitation requires the attacker to have sufficient privileges on the remote MISP server to inject a crafted event identifier, and requires a victim user to visit the remote event preview index. If those conditions are met, the attacker can run arbitrary scripts, hijack sessions, or perform other actions within the victim’s authenticated session.
OpenCVE Enrichment