CVE-2017-13671: Misp-Project Misp

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.

Affected products

Published 2017-08-24. Last modified 2026-06-22.