天下漏洞,尽知其名
MEDIUM

CVE-2026-103321 MISP 事件图预览存储型 XSS 漏洞

影响攻击者可在受害者浏览器中执行任意 JavaScript,窃取会话或敏感数据

MEDIUM
暂无 CVSS 评分
AI 研判

MISP 的事件图预览功能存在存储型跨站脚本漏洞。事件图预览图片字段在服务端未做校验即被存储,客户端又通过字符串拼接将其渲染进 img 标签的 src 属性,导致可注入任意脚本。

影响范围

MISP

MISP 修复提交之前的版本,即 v2.5.48 及更早版本受影响。

漏洞详情

漏洞类型为存储型 XSS,成因是服务端未对事件图预览图片字段进行校验,客户端在渲染时以字符串拼接方式写入 img 元素的 src 属性,攻击者可构造特殊值突破属性上下文注入脚本。拥有创建或修改事件图条目权限的已认证用户可植入恶意载荷,当其他用户查看事件图并触发预览弹窗时脚本即被执行。

利用条件与风险

利用需攻击者具备创建或修改事件图条目的已认证权限,且需诱导受害者查看事件图并触发预览弹窗;成功后可窃取会话令牌、Cookie 或敏感数据,并以受害者身份执行操作。

修复建议

升级至包含修复提交的 MISP 版本(v2.5.48 之后);临时缓解可对事件图预览图片字段进行严格校验与转义,并在客户端避免使用字符串拼接渲染属性。

原始情报

MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.

The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element’s src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.

Preconditions:

– An authenticated MISP user with the ability to create or modify an event graph entry.

– A second user (the victim) who views the event graph and triggers the preview popover.

Impact:

– Execution of arbitrary JavaScript in the victim’s browser within the MISP application context.

– Potential theft of session tokens, cookies, or sensitive data accessible to the victim’s browser.

– Potential for performing actions on behalf of the victim within the MISP application.

Affected: MISP versions prior to the fix (commit applied after v2.5.48).