Security readout for executives and security teams
Plain-English summary
CVE-2021-37743 is a stored cross-site scripting issue in MISP 2.4.147. A malicious value can be saved and later run in a user’s browser when galaxy cluster elements are viewed in JSON format. This can affect analyst trust in displayed threat-intelligence data and may expose session-dependent actions.
Executive priority
Treat this as a targeted hygiene item for MISP owners rather than an emergency. Prioritize promptly if MISP stores partner-supplied or broadly editable threat-intelligence content, because stored XSS can affect trusted analyst workflows.
Technical view
The CVE record identifies app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 as allowing stored XSS during JSON-format viewing of galaxy cluster elements. The supplied sources do not provide CVSS, CWE, required privileges, affected version range beyond 2.4.147, or detailed remediation instructions.
Likely exposure
Known exposure is MISP 2.4.147. The supplied record does not identify other affected versions, deployment conditions, or whether default configurations are vulnerable.
Exploitation context
No active exploitation is stated in the supplied sources, and the CVE is not listed as KEV. Stored XSS generally depends on getting malicious content persisted and then viewed by a user, but the exact attacker path is not documented here.
Researcher notes
Evidence is sparse. The public record names one vulnerable file, one product version, and stored XSS behavior. It does not document payload mechanics, privilege requirements, exploit maturity, or fixed release numbers. Avoid broad version claims without checking MISP advisories or release history.
Mitigation direction
- Identify any MISP 2.4.147 deployments.
- Review the referenced MISP commit for the relevant code change.
- Check official MISP release guidance for the corrected version.
- Upgrade or patch only according to MISP guidance.
- Restrict who can create or modify galaxy cluster content.
Validation and detection
- Confirm deployed MISP version and build provenance.
- Verify whether commit f318f7c0ddac7dfd2b1f246fd8f488d9dfc3a4bf is present.
- Review access controls around galaxy cluster element management.
- Check security logs for unusual galaxy cluster content changes.
- Confirm analysts use patched instances before viewing untrusted content.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-37743 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/MISP/MISP/commit/f318f7c0ddac7dfd2b1f246fd8f488d9dfc3a4bfCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
