CVE-2024-58129

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
28/03/2025
Last modified:
08/07/2025

Description

In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* 2.4.193 (excluding)