Описание
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| precise | not-affected | pre 1.3.0-rc.2 |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | needs-triage | |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | DNE |
Показывать по
10
2.6 Low
CVSS2
4.7 Medium
CVSS3
Связанные уязвимости
CVSS3: 4.7
nvd
почти 9 лет назад
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
CVSS3: 4.7
debian
почти 9 лет назад
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content ...
CVSS3: 4.7
github
больше 3 лет назад
MantisBT XSS through weak CSP when using Gravatar plugin
2.6 Low
CVSS2
4.7 Medium
CVSS3