Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16514

Опубликовано: 20 июн. 2019
Источник: debian

Описание

A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-13055.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisremovedpackage

Примечания

  • https://mantisbt.org/bugs/view.php?id=24731

Связанные уязвимости

CVSS3: 4.7
nvd
больше 6 лет назад

A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-13055.

CVSS3: 6.1
github
больше 3 лет назад

MantisBT cross-site scripting (XSS) vulnerability through crafted PATH_INFO