Impact
MISP includes a stored cross‑site scripting vulnerability in the default theme’s Galaxies index page. When a MISP instance synchronizes with unknown galaxy clusters, it displays sample tag names in an administrative notice that is written directly into the page without HTML escaping. A user with tag‑editor privileges can create a galaxy tag containing malicious script. When an administrator later views the Galaxies index page, the script is executed in the administrator’s browser, allowing the attacker to read session data, perform actions on the administrator’s behalf, or otherwise compromise the browser context. The server process is not directly abused, and the Overmind theme already applies proper escaping, so only the default theme is affected.
Affected Systems
MISP, version 2.5.47 and earlier
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack requires an attacker to have tag‑editor access to create the malicious tag and requires that an administrator view the Galaxies index page using the default theme. The exploit only compromises the administrator’s browser session and does not impact the MISP server process.
OpenCVE Enrichment