CVE-2017-15216: Misp-Project Misp
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.
Affected products
- Misp-Project Misp: up to and including 2.4.80
Published 2017-10-10. Last modified 2026-06-17.