Cross-Site Scripting Vulnerability in MISP Event Timeline Widget
CVE-2023-49926
6.1MEDIUM
What is CVE-2023-49926?
The MISP platform has a vulnerability located in the event timeline widget found in app/Lib/Tools/EventTimelineTool.php prior to version 2.4.179. This vulnerability allows attackers to inject arbitrary scripts into web pages viewed by users, potentially leading to unauthorized actions or data theft. It is crucial for users to upgrade to the latest version to mitigate the security risks associated with this flaw.
