Mantisbt · Mantisbt · CVE-2018-13055
**Name of the Vulnerable Software and Affected Versions**
MantisBT versions 2.1.0 through 2.15.0
**Description**
A cross-site scripting (XSS) issue exists in the View Filters page, allowing remote attackers to inject arbitrary code through a crafted PATH INFO, provided that the Content Security Policy (CSP) settings permit it.
**Recommendations**
For MantisBT versions 2.1.0 through 2.15.0, update to a version that includes a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.