---
id: CVE-2017-13671
title: >-
  app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via
  comments
summary: >-
  app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via
  comments. It only impacts the users of the same instance because the comment
  field is not part of the MISP synchronisation.
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: misp-project
product: misp
affected:
  - misp <= 2.4.78
published: '2017-08-24'
updated: '2026-06-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-13671'
references:
  - url: 'http://www.securityfocus.com/bid/100533'
    label: cve@mitre.org
  - url: >-
      https://github.com/MISP/MISP/commit/6eba658d4a648b41b357025d864c19a67412b8aa
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/100533'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/MISP/MISP/commit/6eba658d4a648b41b357025d864c19a67412b8aa
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01278
epssPercentile: 0.68225
ingestedAt: '2026-06-29T13:24:33.203Z'
---

## Overview

app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.

## Affected

- `misp <= 2.4.78`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
