天下漏洞,尽知其名
MEDIUM

CVE-2026-104900 MISP 远程事件预览存储型 XSS 漏洞

影响攻击者可在受害者浏览器中执行任意 JavaScript

MEDIUM
暂无 CVSS 评分
AI 研判

MISP 在远程事件预览的索引表渲染中存在存储型跨站脚本漏洞。count 字段模板对关联链接 URL 做了转义,但字段值本身未进行 HTML 编码。攻击者可在已链接的远程 MISP 服务器上创建或修改带有恶意标识符的事件,当本地实例用户查看远程事件预览索引时触发脚本执行。

影响范围

MISP

受影响版本为 MISP < 2.5.48。

漏洞详情

漏洞类型为存储型 XSS,成因是模板对 count 字段值缺少 HTML 编码输出。攻击者需在已连接的远程 MISP 服务器上具备创建或修改事件的权限,构造包含 HTML/JavaScript 标记的事件标识符。本地用户浏览远程事件预览索引页面时,未转义的值被直接渲染,导致脚本在受害者会话中执行。

利用条件与风险

利用前提是本地实例已配置并连接远程 MISP 服务器,且攻击者在该远程服务器上拥有创建或修改事件的权限,同时需诱导本地用户查看远程事件预览索引。成功利用可导致会话劫持、数据窃取或以受害者身份执行未授权操作。

修复建议

建议升级至 MISP 2.5.48 或更高版本。临时缓解措施包括限制远程 MISP 服务器的连接与事件创建权限,或对远程事件预览中的字段输出进行 HTML 编码。

原始情报

MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated link URL but rendered the field value without HTML encoding. An attacker with the ability to create or modify events on a linked (remote) MISP server could craft an event identifier containing HTML or JavaScript markup. When a user on the local MISP instance views the remote event preview index, the unescaped value is rendered directly in the browser, allowing arbitrary script execution in the victim’s session.

Preconditions:

– A linked/remote MISP server is configured and connected to the local instance.

– The attacker has sufficient access on the linked server to create or modify an event with a crafted identifier.

– A victim user on the local instance views the remote event preview index page.

Impact:

– Execution of arbitrary JavaScript in the context of the MISP web application.

– Potential session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user.

Affected versions: <2.5.48.