Impact
MISP contains an XSS vulnerability in the event preview page that renders tag identifiers within an inline JavaScript onclick attribute. The tag ID is HTML‑escaped but not sanitized for the JavaScript string context, so a malicious linked MISP server can supply a tag ID containing characters such as a single quote to break out of the JavaScript string literal and inject arbitrary scripting code. When an authenticated user clicks on the affected tag, the injected script runs in the context of the user's browser session, potentially allowing session hijacking, data exfiltration, or execution of unintended actions on the user's behalf.
Affected Systems
The vulnerability affects installations of MISP prior to the fix commit that casts the remote tag ID to an integer. Versions older than v2.5.48 are considered vulnerable, though the exact boundary is unconfirmed. Any system configured with one or more linked/remote MISP servers that uses the event preview feature is in scope.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available, so the exploitation probability is unclear. The vulnerability is not listed in CISA's KEV catalog. An attacker must control a linked remote server, supply a crafted tag ID, and the victim must have authenticated access to the event preview and click the affected tag. The exploit happens locally in the user's browser, so it requires user interaction rather than remote code execution, limiting the attack surface but still posing a significant risk to the affected user.
OpenCVE Enrichment