CVE-2024-58129
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-58129 is a vulnerability affecting the MISP platform before version 2.4.193. This issue permits attackers with administrative privileges to set the menu_custom_right_link_html parameter via the user interface. As a result, they can carry out Cross-Site Scripting (XSS) attacks, which can impact every page on the platform. This vulnerability poses a significant risk, as XSS attacks can lead to the theft of sensitive information or unauthorized access to user accounts. Administrators are urged to upgrade to the latest version of MISP to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- MISP
Affected Vendors
- Misp