# MISP 2.4.107 patches three XSS flaws

Published: 2019-05-13 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/06299e39-de90-526d-9c5e-5648a5591304/misp-2-4-107-patches-three-xss-flaws

> MISP 2.4.107 fixes three persistent XSS vulnerabilities and adds new features like YARA export and object merging.

MISP, the open-source threat intelligence platform, released version 2.4.107 addressing three persistent cross-site scripting vulnerabilities reported by João Lucas Melo Brasio of Elytron Security S.A. The flaws (CVE-2019-11812, CVE-2019-11813, CVE-2019-11814) affect the discussion interface, attribute value fields, and image title handling respectively, allowing JavaScript injection that could execute in the context of other users viewing affected content.

Beyond the security fixes, the release introduces several new capabilities including similar-object detection and merging tools, native YARA and YARA-JSON export functionality, improved API options for warninglist hits and ATT&CK matrix exports, and platform support expansion to OpenBSD 6.5 and Debian 9.9. New MISP modules were also added for document parsing (PDF, PPT, DOCX, XLS) and VMRay sandbox integration.

The vulnerabilities are persistent XSS issues requiring user interaction (e.g., clicking a crafted link) rather than remotely exploitable without interaction. As MISP is widely used by security teams and CERTs for threat intelligence sharing, organizations running self-hosted instances should update to 2.4.107 to mitigate the risk of session hijacking or unauthorized actions via injected scripts within their collaborative platform.

## Mentioned in this report

- Vulnerabilities: CVE-2019-11812, CVE-2019-11813, CVE-2019-11814

Source reporting: https://www.misp-project.org/2019/05/13/misp.2.4.107.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/06299e39-de90-526d-9c5e-5648a5591304/misp-2-4-107-patches-three-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
