CVE-2015-5720
03.09.2016, 20:59
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxification.js.
| Vendor | Product | Version |
|---|---|---|
| misp-project | malware_information_sharing_platform | 𝑥 ≤ 2.3.89 |
𝑥
= Vulnerable software versions
References