Опубликовано: 17 фев. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6
CVSS3: 4.7
Описание
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| precise | not-affected | pre 1.3.0-rc.2 |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | needs-triage | |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | DNE |
Показывать по
10
EPSS
Процентиль: 61%
0.01003
Низкий
2.6 Low
CVSS2
4.7 Medium
CVSS3
Связанные уязвимости
CVSS3: 4.7
nvd
больше 9 лет назад
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
CVSS3: 4.7
debian
больше 9 лет назад
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content ...
CVSS3: 4.7
github
больше 4 лет назад
MantisBT XSS through weak CSP when using Gravatar plugin
EPSS
Процентиль: 61%
0.01003
Низкий
2.6 Low
CVSS2
4.7 Medium
CVSS3