app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.
원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-13671
원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-13671
댓글 0
번호 | 제목 | 글쓴이 | 날짜 | 조회 수 |
---|---|---|---|---|
287 | CVE-2015-7259 | 관리자 | 2017.08.27 | 26 |
286 | CVE-2015-7258 | 관리자 | 2017.08.27 | 42 |
» | CVE-2017-13671 | 관리자 | 2017.08.27 | 37 |
284 | CVE-2017-9555 | 관리자 | 2017.08.27 | 22 |
283 | CVE-2017-12879 | 관리자 | 2017.08.27 | 32 |
282 | CVE-2017-9511 | 관리자 | 2017.08.27 | 39 |
281 | CVE-2017-12074 | 관리자 | 2017.08.27 | 34 |
280 | CVE-2017-13669 | 관리자 | 2017.08.27 | 27 |
279 | CVE-2017-9507 | 관리자 | 2017.08.27 | 109 |
278 | CVE-2017-9509 | 관리자 | 2017.08.27 | 178 |
277 | CVE-2017-9508 | 관리자 | 2017.08.27 | 52 |
276 | CVE-2017-12679 | 관리자 | 2017.08.27 | 24 |
275 | CVE-2017-9510 | 관리자 | 2017.08.27 | 38 |
274 | CVE-2017-9512 | 관리자 | 2017.08.27 | 33 |
273 | CVE-2017-11424 | 관리자 | 2017.08.27 | 24 |