First published: Sat Nov 09 2019(Updated: )
MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | >=1.2.0<1.2.2 | |
debian/mantis |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2802 is a vulnerability in MantisBT 1.2.x before 1.2.2 that insecurely handles attachments and MIME types, leading to potential cross-domain scripting or browser attacks.
CVE-2009-2802 allows arbitrary inline attachment rendering in MantisBT, which could lead to cross-domain scripting or other browser attacks.
The severity of CVE-2009-2802 is medium, with a severity value of 6.1.
To fix CVE-2009-2802, it is recommended to update MantisBT to version 1.2.2 or later.
You can find more information about CVE-2009-2802 at the following references: [https://mantisbt.org/blog/archives/mantisbt/113](https://mantisbt.org/blog/archives/mantisbt/113), [https://security-tracker.debian.org/tracker/CVE-2009-2802](https://security-tracker.debian.org/tracker/CVE-2009-2802), [https://mantisbt.org/bugs/view.php?id=11952](https://mantisbt.org/bugs/view.php?id=11952).