In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
References
| Link | Resource |
|---|---|
| https://github.com/MISP/MISP/commit/1f39deb572da7ecb5855e30ff3cc8cbcaa0c1054 | Patch |
| https://github.com/MISP/MISP/compare/v2.5.27...v2.5.28 | Release Notes |
| https://github.com/franckferman/CVE-2025-67906 | Third Party Advisory |
| https://github.com/franckferman/GCVE-1-2025-0030 | Third Party Advisory |
| https://vulnerability.circl.lu/vuln/gcve-1-2025-0031 | Third Party Advisory |
| https://github.com/franckferman/CVE-2025-67906 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-12-15 04:15
Updated : 2025-12-21 01:15
NVD link : CVE-2025-67906
Mitre link : CVE-2025-67906
CVE.ORG link : CVE-2025-67906
JSON object : View
Products Affected
misp
- misp
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
