PT-2019-6863 · Mantisbt · Mantisbt

Atrol

+1

·

Published

2019-10-31

·

Updated

2019-11-06

·

CVE-2013-1932

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MantisBT version 1.2.13
Description A cross-site scripting (XSS) issue exists in the configuration report page, specifically in the adm config report.php file, allowing remote authenticated users to inject arbitrary web script or HTML via a project name.
Recommendations For MantisBT version 1.2.13, consider restricting access to the configuration report page until a fix is available. As a temporary workaround, avoid using the project name field in the adm config report.php file to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1932

Affected Products

Mantisbt