VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.112 patches stored XSS flaw

routine vulnerability technology

MISP 2.4.112 fixes a stored XSS vulnerability in the event-graph view (CVE-2019-14286) along with numerous API and performance improvements.

The MISP project released version 2.4.112, addressing a stored cross-site scripting vulnerability (CVE-2019-14286) in app/webroot/js/event-graph.js. The flaw is triggered when a user toggles the event graph view on a maliciously crafted MISP event, allowing injected script to execute in the context of the viewing user. The vulnerability was reported by David Heise and is fixed in this release.

Beyond the security fix, the update includes a range of API and sync improvements, including new restSearch parameters (includeSightings, includeCorrelations), performance boosts for remote instance previews, a new 'weakness' attribute type, and updates to MISP galaxies incorporating the July edition of the MITRE ATT&CK model. Users are strongly encouraged to upgrade to 2.4.112 to remediate the XSS issue.

Mentioned in this report

Vulnerabilities CVE-2019-14286

Source reporting: https://www.misp-project.org/2019/08/01/misp.2.4.112.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free