# MISP 2.4.112 patches stored XSS flaw

Published: 2019-08-01 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/1af434fe-c855-56d8-a256-254923ffc524/misp-2-4-112-patches-stored-xss-flaw

> MISP 2.4.112 fixes a stored XSS vulnerability in the event-graph view (CVE-2019-14286) along with numerous API and performance improvements.

The MISP project released version 2.4.112, addressing a stored cross-site scripting vulnerability (CVE-2019-14286) found in app/webroot/js/event-graph.js. The flaw could be triggered when a user toggles the event graph view on a maliciously crafted MISP event, potentially allowing script execution in the context of the viewing user. The issue was reported by David Heise and has been fixed in this release.

Beyond the security fix, the release includes a range of API enhancements such as new restSearch parameters (includeSightings, includeCorrelations), improved sync/preview performance for remote instances, a new CLI cleanCaches command, and the ability to disable background processing and DB logging on demand. The data model was extended with a new 'weakness' (CWE) attribute type, and misp-modules gained an advanced CVE module supporting import of CVEs with associated weaknesses and ATT&CK techniques. MISP galaxies were updated to include the July edition of the MITRE ATT&CK model.

Organizations running MISP instances are encouraged to upgrade to 2.4.112 promptly to remediate the stored XSS issue, particularly given that threat intelligence platforms often ingest data from external, less-trusted sources, increasing the risk of a malicious event triggering the vulnerability.

## Mentioned in this report

- Vulnerabilities: CVE-2019-14286

Source reporting: https://www.misp-project.org/2019/08/01/misp.2.4.112.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1af434fe-c855-56d8-a256-254923ffc524/misp-2-4-112-patches-stored-xss-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
