MEDIUM
An XSS issue was discovered in admin/install.php in MantisBT before 1.3.12 and 2.x before 2.5.2
Published Aug 1, 2017
6.1
MEDIUMCVSS 3.1
EPSS 2.94%
Description
An XSS issue was discovered in admin/install.php in MantisBT before 1.3.12 and 2.x before 2.5.2. Some variables under user control in the MantisBT installation script are not properly sanitized before being output, allowing remote attackers to inject arbitrary JavaScript code, as demonstrated by the $f_database, $f_db_username, and $f_admin_username variables. This is mitigated by the fact that the admin/ folder should be deleted after installation, and also prevented by CSP.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://openwall.com/lists/oss-security/2017/08/01/1 x_refsource_CONFIRMMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2017/08/01/2 x_refsource_CONFIRMMailing ListThird Party Advisory
- http://www.securitytracker.com/id/1039030 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-98xr-mmq5-vc5h Advisory
- https://github.com/mantisbt/mantisbt/commit/17f9b94f031ba93ae2a727bca0e68458ecd08fb0 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/mantisbt/mantisbt/commit/c73ae3d3d4dd4681489a9e697e8ade785e27cba5 x_refsource_CONFIRMPatchThird Party Advisory
- https://mantisbt.org/bugs/view.php?id=23146 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-12061
- https://web.archive.org/web/20170811053146/http://www.securitytracker.com/id/1039030
| Link | Providers | Tags |
|---|---|---|
| http://openwall.com/lists/oss-security/2017/08/01/1 | x_refsource_CONFIRMMailing ListThird Party Advisory | |
| http://openwall.com/lists/oss-security/2017/08/01/2 | x_refsource_CONFIRMMailing ListThird Party Advisory | |
| http://www.securitytracker.com/id/1039030 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://github.com/advisories/GHSA-98xr-mmq5-vc5h | Advisory | |
| https://github.com/mantisbt/mantisbt/commit/17f9b94f031ba93ae2a727bca0e68458ecd08fb0 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://github.com/mantisbt/mantisbt/commit/c73ae3d3d4dd4681489a9e697e8ade785e27cba5 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://mantisbt.org/bugs/view.php?id=23146 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-12061 | ||
| https://web.archive.org/web/20170811053146/http://www.securitytracker.com/id/1039030 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 1, 2017
Updated Aug 5, 2024
Reserved Jul 31, 2017
Link CVE-2017-12061
CISA Vulnrichment
GHSA-98XR-MMQ5-VC5H Updated n/a