MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.
| Software | From | Fixed in |
|---|---|---|
| misp-project / misp | - | 2.4.80.x |