MISP prior to 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
misp-project misp |