{"id":"CVE-2017-16802","details":"In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.","modified":"2026-08-07T14:49:01.016895Z","published":"2017-11-13T16:29:00.263Z","references":[{"type":"FIX","url":"https://github.com/MISP/MISP/commit/a659664447a7b2a383cb9e0f6b43dcb43ec69194"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/misp/misp","events":[{"introduced":"74c1f75e5292a977c808fb8f12a51b626103d145"},{"last_affected":"74c1f75e5292a977c808fb8f12a51b626103d145"},{"fixed":"a659664447a7b2a383cb9e0f6b43dcb43ec69194"}],"database_specific":{"cpe":"cpe:2.3:a:misp-project:misp:2.4.82:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.4.82"},{"last_affected":"2.4.82"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2.4.82","v2.4.82"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16802.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}