CVE-2010-2574: XSS
Cross-site scripting (XSS) vulnerability in manageprojcatadd.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2574?
CVE-2010-2574 has a moderate severity level as it allows authenticated administrators to execute arbitrary web scripts.
How do I fix CVE-2010-2574?
To fix CVE-2010-2574, upgrade MantisBT to a version higher than 1.2.2 which addresses the XSS vulnerability.
Who is affected by CVE-2010-2574?
CVE-2010-2574 affects MantisBT version 1.2.2 and allows remote authenticated administrators to exploit the XSS vulnerability.
What type of vulnerability is CVE-2010-2574?
CVE-2010-2574 is categorized as a cross-site scripting (XSS) vulnerability.
Are there any known exploits for CVE-2010-2574?
Yes, CVE-2010-2574 can be exploited by injecting arbitrary HTML or web scripts through the name parameter in the Add Category action.