MEDIUM
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version
Published Oct 31, 2019
6.1
MEDIUMCVSS 3.1
EPSS 2.35%
Description
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.
Affected products
-
- Version 1.2.14StatusaffectedConstraints-
- Version
Configuration 2
OR
- 17
- 18
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103438.html x_refsource_MISCThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103459.html x_refsource_MISCThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/04/06/4 x_refsource_MISCMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/58889 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1931 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://mantisbt.org/bugs/view.php?id=15511 x_refsource_CONFIRMVendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2013-1931 x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103438.html | x_refsource_MISCThird Party Advisory | |
| http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103459.html | x_refsource_MISCThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2013/04/06/4 | x_refsource_MISCMailing ListThird Party Advisory | |
| http://www.securityfocus.com/bid/58889 | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1931 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://mantisbt.org/bugs/view.php?id=15511 | x_refsource_CONFIRMVendor Advisory | |
| https://security-tracker.debian.org/tracker/CVE-2013-1931 | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 31, 2019
Updated Aug 6, 2024
Reserved Feb 19, 2013
Link CVE-2013-1931
CISA Vulnrichment
Updated n/a