First published: Mon Aug 09 2010(Updated: )
Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
MantisBT | =1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2574 has a moderate severity level as it allows authenticated administrators to execute arbitrary web scripts.
To fix CVE-2010-2574, upgrade MantisBT to a version higher than 1.2.2 which addresses the XSS vulnerability.
CVE-2010-2574 affects MantisBT version 1.2.2 and allows remote authenticated administrators to exploit the XSS vulnerability.
CVE-2010-2574 is categorized as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2010-2574 can be exploited by injecting arbitrary HTML or web scripts through the name parameter in the Add Category action.