MISP 的 ID Translator(ID 翻译器)功能中存在跨站脚本(XSS)漏洞。当用户查看 ID Translator 页面时,应用程序会查询已链接(远程)MISP 服务器以获取相应的事件标识符。远程服务器返回的事件 ID 在 HTML 输出中未经适当的输出编码就直接渲染。 恶意或已被入侵的链接服务器可以返回包含任意 HTML 或 JavaScript 标记的构造事件 ID。这些标记会在主机组织中任何查看该 ID Translator 页面的用户的浏览器中渲染,从而导致会话劫持、凭证窃取或其他客户端攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104908 | 7.1 HIGH | MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and D |
| CVE-2026-104912 | 7.1 HIGH | MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data |
| CVE-2026-104906 | 6.2 MEDIUM | MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output |
| CVE-2026-104900 | 5.3 MEDIUM | MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index |
| CVE-2026-104910 | 5.3 MEDIUM | MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization |
| CVE-2026-104914 | 5.3 MEDIUM | MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Pa |
| CVE-2026-104907 | 4.8 MEDIUM | MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler |
No comments yet