Количество 3
Количество 3
CVE-2019-15074
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed.
CVE-2019-15074
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 ha ...
GHSA-gg4j-279j-22ph
MantisBT allows cross-site scripting (XSS) via crafted filename
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-15074 The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed. | CVSS3: 9.6 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15074 The Timeline feature in my_view_page.php in MantisBT through 2.21.1 ha ... | CVSS3: 9.6 | 1% Низкий | больше 6 лет назад | |
GHSA-gg4j-279j-22ph MantisBT allows cross-site scripting (XSS) via crafted filename | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу