CVE-2022-47928

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
22/12/2022
Last modified:
09/01/2024

Description

In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:misp-project:malware_information_sharing_platform:*:*:*:*:*:*:*:* 2.4.167 (excluding)