# MISP 2.4.126 patches persistent XSS flaw

Published: 2020-06-04 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/b8837bb2-ea42-5097-b495-e2e6bc27dcbe/misp-2-4-126-patches-persistent-xss-flaw

> MISP 2.4.126 fixes a persistent XSS vulnerability (CVE-2020-13153) triggered via correlated attributes in the freetext import tool.

MISP, the open-source threat intelligence sharing platform, released version 2.4.126, addressing a persistent cross-site scripting vulnerability tracked as CVE-2020-13153. The flaw could be triggered when an analyst uses the freetext import tool to correlate an attribute containing a JavaScript payload embedded in the comment field; simply hovering over the resulting correlation in the UI would execute the malicious script in the analyst's browser session.

The vulnerability was reported by a researcher and fixed in this release alongside several quality-of-life improvements, including a communities webpage generation tool and an experimental CLI-only force-pull method for administrators to override local modifications with remote data. The update also bundles refreshed misp-objects, misp-taxonomies, and misp-galaxy content. No evidence of active exploitation is mentioned; this is a routine maintenance and security patch release.

## Mentioned in this report

- Vulnerabilities: CVE-2020-13153

Source reporting: https://www.misp-project.org/2020/06/04/misp.2.4.126.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b8837bb2-ea42-5097-b495-e2e6bc27dcbe/misp-2-4-126-patches-persistent-xss-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
