CVE-2017-15216: Misp-Project Misp

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.

Affected products

Published 2017-10-10. Last modified 2026-06-17.