DOM-Based XSS Vulnerability in MISP Web Application by MISP Technology
CVE-2018-11245
6.1MEDIUM
What is CVE-2018-11245?
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the webroot JavaScript file (misp.js) of MISP version 2.4.91. This flaw allows attackers to execute arbitrary JavaScript code within the user's browser, affecting the integrity of the application and potentially compromising user data. Exploitation of this vulnerability can occur due to improper handling of cortex type attributes, making it essential for users to apply recommended security patches promptly.
