# MISP 2.4.175 patches two XSS flaws

Published: 2023-08-24 · Severity: low
Canonical: https://vorant.io/reports/3d2e5e66-bd5b-54de-9830-a774d4977956/misp-2-4-175-patches-two-xss-flaws

> MISP 2.4.175 fixes two reflected XSS vulnerabilities in the events index and dashboard controller, plus adds features and bug fixes.

The MISP project released version 2.4.175, a maintenance update addressing two reflected cross-site scripting vulnerabilities alongside a range of functional improvements and bug fixes. CVE-2023-40224 affects the events index view, while CVE-2023-41098 stems from unsanitized handling of the id parameter in the dashboard edit controller, both allowing XSS injection. Neither vulnerability has any indication of active exploitation; they were responsibly disclosed by the BeDisruptive OSS Team and the Centre for Cyber Security Belgium (CCB).

Beyond the security fixes, the release includes several usability and functionality improvements such as new dashboard widget timeframe options, enrichment support for complete MISP objects, new feeds, and improved diagnostics for offline instances. It also updates MISP object templates (including new malware and malware-analysis objects for STIX 2.1 support), refreshes the threat actor and tool galaxies, and adds new warning-list sources including Zscaler IP ranges and OpenAI crawler IPs. This is a routine platform maintenance release rather than an advisory about active threats.

## Mentioned in this report

- Vulnerabilities: CVE-2023-40224, CVE-2023-41098

Source reporting: https://www.misp-project.org/2023/08/24/misp.2.4.175.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3d2e5e66-bd5b-54de-9830-a774d4977956/misp-2-4-175-patches-two-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
