Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcfc-9gm4-cqj8

Опубликовано: 21 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks.

MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks.

EPSS

Процентиль: 63%
0.0045
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks.

CVSS3: 6.1
nvd
около 6 лет назад

MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks.

CVSS3: 6.1
debian
около 6 лет назад

MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME ty ...

EPSS

Процентиль: 63%
0.0045
Низкий