Cross-Site Scripting Vulnerability in MISP AuthKey Display
CVE-2023-24070
6.1MEDIUM
What is CVE-2023-24070?
An XSS vulnerability was identified in the MISP application specifically within the authkey display functionality. The issue arises in the app/View/AuthKeys/authkey_display.ctp file, where the application improperly handles input from the Referer field. This flaw allows attackers to inject and execute malicious scripts, which could compromise user sessions or manipulate the content viewed by users. It's crucial for administrators to apply patches and monitor their MISP installations to mitigate potential threats from this vulnerability.
