MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.
The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.
Preconditions:
Impact:
-
Execution of arbitrary JavaScript in the victim's browser within the MISP application context.
-
Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser.
-
Potential for performing actions on behalf of the victim within the MISP application.
Affected: MISP versions prior to the fix (commit applied after v2.5.48).
The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.