CVE-2021-25325

Publication date

2021-01-19 15:29:58

Family

mitre

State

PUBLISHED

Description

MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.