CVE-2017-12062

An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled.
References
Link Resource
https://mantisbt.org/bugs/view.php?id=23166 Exploit Issue Tracking Vendor Advisory
https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7 Patch Third Party Advisory
http://openwall.com/lists/oss-security/2017/08/01/2 Mailing List Third Party Advisory
http://openwall.com/lists/oss-security/2017/08/01/1 Mailing List Third Party Advisory
http://www.securitytracker.com/id/1039030 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mantisbt:mantisbt:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:mantisbt:mantisbt:2.2.0:*:*:*:*:*:*:*

Information

Published : 2017-08-01 08:29

Updated : 2017-08-15 10:17


NVD link : CVE-2017-12062

Mitre link : CVE-2017-12062


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

mantisbt

  • mantisbt