MEDIUM 5.1 NVD
CVE-2026-103662
MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affe
MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).
The affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator's browser session.
Preconditions:
- The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.
- The victim must be an authenticated site administrator.
- The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).
Security impact:
- Execution of arbitrary client-side script in the context of the administrator's browser.
- Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.
- Potential for performing privileged actions on behalf of the administrator within the MISP interface.
Affected versions: <2.5.48.
References
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.