StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This feature allows an attacker to insert malicious JavaScript code inside the template or its variables, that will be executed in the context of the TheHive application when the HTML report is opened.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-01-19T00:00:00.000Z
Updated: 2025-06-02T15:02:49.867Z
Reserved: 2024-01-11T00:00:00.000Z
Link: CVE-2024-22877

Updated: 2024-08-01T22:51:11.240Z

Status : Modified
Published: 2024-01-19T14:15:13.557
Modified: 2025-06-02T15:15:31.593
Link: CVE-2024-22877

No data.