天下漏洞,尽知其名
MEDIUM

CVE-2026-104907 MISP 远程事件预览页跨站脚本漏洞

影响攻击者可注入并执行任意 JavaScript,窃取会话或冒充用户操作

MEDIUM
暂无 CVSS 评分
AI 研判

MISP 的远程事件预览页面存在跨站脚本漏洞。当本地实例配置了关联的远程 MISP 服务器时,事件预览会将标签标识符渲染进内联 JavaScript 的 onclick 属性中。该标签 ID 虽经 HTML 转义,但未针对 JavaScript 字符串上下文做净化处理,导致恶意远程服务器可注入脚本。

影响范围

MISP

MISP 修复提交之前的版本(描述称 v2.5.48 或更高版本,确切边界未确认),暂无公开的精确受影响版本范围。

漏洞详情

漏洞类型为存储型/反射型跨站脚本(XSS),成因是标签 ID 在写入内联 onclick 的 JavaScript 字符串字面量时仅做了 HTML 转义,未按 JS 字符串上下文进行转义或过滤。恶意关联服务器可在事件中提供包含单引号等字符的标签 ID,从而闭合字符串字面量并注入任意脚本。当已认证用户查看事件预览并与该标签元素交互时,注入脚本会在其浏览器会话中执行。

利用条件与风险

利用前提是本地实例已配置并连接恶意远程 MISP 服务器,且需已认证用户查看事件预览并点击受影响的标签元素,属于需要用户交互的中等风险场景。成功利用可导致会话劫持、数据外泄或以用户身份执行未授权操作。

修复建议

官方修复方案为升级至包含修复提交的 MISP 版本(描述提及 v2.5.48 或更高,确切版本暂无公开信息);临时缓解措施包括谨慎配置可信的关联远程服务器、避免点击来源不可信事件中的标签元素。

原始情报

MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.

Preconditions:

– A linked/remote MISP server is configured and connected to the local instance.

– The linked server supplies a crafted tag ID in an event.

– An authenticated user views the event preview and interacts with the affected tag element.

Impact:

– Arbitrary JavaScript execution in the context of the viewing user’s browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.

Affected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).