Cross-Site Scripting Vulnerability in MISP by GnuHealth Team
CVE-2024-58129
4.8MEDIUM
What is CVE-2024-58129?
A Cross-Site Scripting (XSS) vulnerability exists in MISP that allows attackers with admin privileges to inject malicious scripts via the 'menu_custom_right_link_html' parameter using the user interface. This flaw affects all pages of the application, potentially compromising user data and security. It is crucial for users to update to version 2.4.193 or later to mitigate this issue.
Affected Version(s)
MISP 0 < 2.4.193
