Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-13055

Опубликовано: 03 авг. 2018
Источник: debian
EPSS Низкий

Описание

A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisremovedpackage

Примечания

  • http://github.com/mantisbt/mantisbt/commit/4efac90ed89a5c009108b641e2e95683791a165a

  • https://mantisbt.org/blog/archives/mantisbt/602

  • https://mantisbt.org/bugs/view.php?id=24580

EPSS

Процентиль: 57%
0.00349
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 7 лет назад

A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO.

CVSS3: 6.1
nvd
больше 7 лет назад

A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO.

CVSS3: 6.1
github
больше 3 лет назад

MantisBT allows XSS via View Filters page

EPSS

Процентиль: 57%
0.00349
Низкий