CVE-2017-15216 Information
Feb 14, 2021
cve
Description
MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/MISP/MISP/commit/ca6f4a783a6ba65532dc8767446bda44773ec627 https://www.misp.software/Changelog.txt
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: