PT-2005-4147 · Mantis · Mantis

Publicado

2005-10-27

·

Atualizado

2008-09-05

·

CVE-2005-3337

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mantis versions prior to 0.19.3
Description The issue involves multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web script or HTML. This is possible via unknown vectors involving Javascript and the 'mantis/view all set.php' endpoint.
Recommendations For versions prior to 0.19.3, update to version 0.19.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the 'mantis/view all set.php' endpoint until a patch is available. Avoid using Javascript in unknown vectors in the affected versions until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3337

Produtos afetados

Mantis