CVE-2024-58129
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
28/03/2025
Last modified:
08/07/2025
Description
In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | 2.4.193 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



