VORANT. Threat Intelligence Sign in Get the full feed

MISP patches reflected XSS flaw

medium vulnerability technology

MISP 2.4.105 fixes a reflected XSS vulnerability (CVE-2019-10254) in the default layout template, plus STIX import/export improvements.

The MISP threat intelligence platform project released version 2.4.105, addressing a reflected cross-site scripting vulnerability in the default layout template tracked as CVE-2019-10254. The flaw was reported by Tuscany Internet eXchange's Misp Team - TIX CyberSecurity, and the project recommends all users update immediately.

Beyond the security fix, the release includes a repair for STIX 1.1 import to support additional non-standard namespaces such as CISCP, corrected TLP marking on STIX 1.1 export, a new diagnostic for git sub-module status, replacement of the old export page with an improved restSearch, general UI improvements, and a Russian UI translation. No evidence of active exploitation is mentioned; this is a routine vendor patch advisory.

Mentioned in this report

Vulnerabilities CVE-2019-10254

Source reporting: https://www.misp-project.org/2019/03/28/misp.2.4.105.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free