CVE-2019-11814 describes a persistent Cross-Site Scripting (XSS) vulnerability found in MISP versions prior to 2.4.107, specifically within the app/webroot/js/misp.js component. This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated attacker to inject malicious scripts via image names in titles, requiring user interaction for successful exploitation. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or active exploitation is reported, and community discussion is minimal, the flaw could lead to limited data compromise and integrity issues.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.107CPE matchmatch criteria | cpe:2.3:a:misp-project:misp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.