MISP 的事件属性过滤查询构建器中存在一个反射型跨站脚本(XSS)漏洞。 和 这两个 URL 参数在被序列化为 JSON 并嵌入到 元素中之前,未进行 HTML 转义,而是直接插入到查询构建规则中。 由于 使用了 标志,攻击者可控的值中若包含闭合标签 ,则可能终止外部的 script 元素,从而注入任意的 HTML 或 JavaScript。例如,攻击者可以构造一个包含恶意内容的 URL,将恶意载荷置于上述任一受影响的过滤参数中。 攻击者可以通过诱导已认证的 MISP 用户访问精心构造的 URL 来利用此漏洞。成
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85216 | 9.5 CRITICAL | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials |
| CVE-2026-85236 | 8.8 HIGH | MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request |
| CVE-2026-85237 | 8.6 HIGH | Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass |
| CVE-2026-85221 | 7.6 HIGH | MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attack |
| CVE-2026-85238 | 7.6 HIGH | Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking |
| CVE-2026-85239 | 7.1 HIGH | MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service |
| CVE-2026-85226 | 5.3 MEDIUM | MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Co |
| CVE-2026-85230 | 5.3 MEDIUM | MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection |
No comments yet