# MISP patches reflected XSS flaw

Published: 2019-03-28 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/46937929-ab99-5d95-8222-d0622477f645/misp-patches-reflected-xss-flaw

> MISP 2.4.105 fixes a reflected XSS vulnerability (CVE-2019-10254) in the default layout template, plus STIX import/export improvements.

The MISP threat intelligence platform project released version 2.4.105, addressing a reflected cross-site scripting vulnerability in the default layout template tracked as CVE-2019-10254. The flaw was reported by Tuscany Internet eXchange's Misp Team - TIX CyberSecurity, and the project recommends all users update immediately.

Beyond the security fix, the release includes a repair for STIX 1.1 import to support additional non-standard namespaces such as CISCP, corrected TLP marking on STIX 1.1 export, a new diagnostic for git sub-module status, replacement of the old export page with an improved restSearch, general UI improvements, and a Russian UI translation. No evidence of active exploitation is mentioned; this is a routine vendor patch advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2019-10254

Source reporting: https://www.misp-project.org/2019/03/28/misp.2.4.105.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/46937929-ab99-5d95-8222-d0622477f645/misp-patches-reflected-xss-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
