Impact
A cross‑site scripting flaw exists in the ID Translator of MISP. When the tool retrieves event identifiers from a linked MISP server, the returned event ID is emitted into the page without output encoding. This allows a malicious or compromised linked server to supply a string containing JavaScript or other HTML, which the browser will execute in the context of an authenticated host user, enabling session hijacking, credential theft, or broader client‑side attacks. The likely attack vector is a compromised remote server that returns a crafted event ID, because the application trusts the value returned by the linked server before rendering it.
Affected Systems
All versions of MISP older than 2.5.48 are vulnerable. The issue is only present in the ID Translator feature and affects users who have configured linked servers.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1, reflecting moderate severity. No EPSS score is available, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who can access the ID Translator page and a linked server that can return a malicious event ID. Once the endpoint is reached, the injected content is rendered in the victim’s browser, granting the attacker client‑side execution capabilities.
OpenCVE Enrichment