Description
An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with a crafted name (e.g., 'foobar" onclick="alert(1)').
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-6420 | MantisBT allows XSS on the Edit Filter page via crafted filter name |
Github GHSA |
GHSA-74gh-5j33-vg4w | MantisBT allows XSS on the Edit Filter page via crafted filter name |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:29:51.654Z
Reserved: 2018-07-22T00:00:00.000Z
Link: CVE-2018-14504
No data.
Status : Modified
Published: 2018-08-03T18:29:00.487
Modified: 2024-11-21T03:49:12.887
Link: CVE-2018-14504
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA