# MISP 2.4.123 patches two XSS flaws

Published: 2020-03-10 · Severity: low · Sectors: technology
Canonical: https://vorant.io/reports/8ec3314d-fcc4-5e85-925d-68362b92f58b/misp-2-4-123-patches-two-xss-flaws

> MISP 2.4.123 fixes two XSS vulnerabilities found during a CCB-sponsored pentest and adds a new dashboard system.

MISP, the open-source threat intelligence sharing platform, released version 2.4.123 addressing two cross-site scripting vulnerabilities identified during a penetration test conducted on behalf of the Centre for Cyber Security Belgium (CCB). The vulnerabilities, tracked as CVE-2020-10246 and CVE-2020-10247, have been fixed, alongside broader security posture improvements including password policy enhancements, preventative security headers, and improved user notifications regarding suspicious activity.

The release also introduces a new customisable Dashboard system, developed partly in response to the MISP team's own efforts tracking COVID-19 spread via a Coronavirus-sharing community. The dashboard supports modular widgets, user-specific configurations, and shareable templates. Additionally, a bug causing correlations to disappear after certain attribute edits was identified and resolved, with a full recorrelation triggered on update.

This is a routine software update disclosing and patching low-severity web application vulnerabilities alongside feature enhancements; there is no indication of active exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2020-10246, CVE-2020-10247

Source reporting: https://www.misp-project.org/2020/03/10/misp.2.4.123.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8ec3314d-fcc4-5e85-925d-68362b92f58b/misp-2-4-123-patches-two-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
