CVE-2004-1730: XSS
Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to loginpage.php, (2) e-mail field in signup.php, (3) action parameter to loginselectprojpage.php, or (4) hidestatus parameter to viewallset.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1730?
CVE-2004-1730 is considered to be of medium severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2004-1730?
To mitigate CVE-2004-1730, you should upgrade Mantis bugtracker to a version that is not vulnerable to this cross-site scripting issue.
Which versions of Mantis are affected by CVE-2004-1730?
CVE-2004-1730 affects multiple versions of Mantis, specifically those prior to version 0.15.12.
What types of input can exploit CVE-2004-1730?
CVE-2004-1730 can be exploited through specific input fields, including the return parameter to login_page.php and the email field in signup.php.
What are the potential impacts of CVE-2004-1730?
The exploitation of CVE-2004-1730 may allow remote attackers to inject arbitrary web scripts or HTML, leading to various security issues such as session hijacking.