MEDIUM
An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0
Published Aug 3, 2018
6.1
MEDIUMCVSS 3.0
EPSS 1.63%
Description
An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with a crafted name (e.g., 'foobar" onclick="alert(1)').
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://github.com/mantisbt/mantisbt/commit/8b5fa243dbf04344a55fe880135ec149fc1f439f x_refsource_CONFIRMPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-6420 Advisory
- https://github.com/advisories/GHSA-74gh-5j33-vg4w Advisory
- https://mantisbt.org/blog/archives/mantisbt/602 x_refsource_CONFIRMVendor Advisory
- https://mantisbt.org/bugs/view.php?id=24608 x_refsource_CONFIRMExploitIssue TrackingPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-14504
| Link | Providers | Tags |
|---|---|---|
| http://github.com/mantisbt/mantisbt/commit/8b5fa243dbf04344a55fe880135ec149fc1f439f | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-6420 | Advisory | |
| https://github.com/advisories/GHSA-74gh-5j33-vg4w | Advisory | |
| https://mantisbt.org/blog/archives/mantisbt/602 | x_refsource_CONFIRMVendor Advisory | |
| https://mantisbt.org/bugs/view.php?id=24608 | x_refsource_CONFIRMExploitIssue TrackingPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-14504 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 3, 2018
Updated Aug 5, 2024
Reserved Jul 22, 2018
Link CVE-2018-14504
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-74GH-5J33-VG4W