PT-2017-9085 · Mantisbt+1 · Mantisbt+1
J_Schultz
·
Published
2017-02-17
·
Updated
2022-05-17
·
CVE-2016-7111
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MantisBT versions prior to 1.3.1
MantisBT versions 2.x prior to 2.0.0-beta.2
Description
The issue allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors when the Gravatar plugin is used, due to a weak Content Security Policy.
Recommendations
For MantisBT versions prior to 1.3.1, update to version 1.3.1 or later.
For MantisBT versions 2.x prior to 2.0.0-beta.2, update to version 2.0.0-beta.2 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gravatar
Mantisbt