Date: 13.09.2023 Affected Vendor: CIRCL – Computer Incident Response Center Luxembourg Affected Product: MISP – Malware Information Sharing Platform & Open Standards For Threat Information Sharing – https://www.misp-project.org/ Vulnerable Version: 2.4.176 Fixed Version: 2.4.177 Vulnerability Details: The "selectGalaxy" action of the "Galaxies" controller in MISP is vulnerable to reflected XSS. When the victim opens a malicious URL and clicks on one of the available buttons, the malicious script is triggered. CVE: CVE-2023-48659 Credits: Dawid Czarnecki References: - https://cvepremium.circl.lu/cve/CVE-2023-48659 - https://github.com/MISP/MISP/compare/v2.4.175...v2.4.176 - https://github.com/MISP/MISP/commit/37ecf81b84a01baa4d4b1fade4de94a9018c32ed