Impact
The vulnerability is a stored cross‑site scripting flaw in the TAXII object viewer. When a victim opens a malicious TAXII object, the server renders unescaped JSON string properties inside an HTML pre block, allowing an attacker to inject and execute arbitrary JavaScript in the context of the victim’s MISP session. This can lead to theft of session cookies, API keys, or other sensitive data and enable the attacker to perform actions as the authenticated user.
Affected Systems
The flaw affects MISP releases prior to 2.5.48. Users running MISP versions earlier than 2.5.48 are susceptible, regardless of their operating system, as the issue originates in the web application itself.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no current mass exploitation. However, the attack requires a crafted TAXII object and an authenticated MISP user who views the object, making it a targeted, web‑based exploit that can be executed with any gallery or subscription mechanism that the MISP instance uses to ingest remote TAXII objects.
OpenCVE Enrichment