CVE-2010-3303: XSS
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.3 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) a plugin name, related to managepluginuninstall.php; (2) an enumeration value or (3) a String value of a custom field, related to core/cfdefs/cfdefstandard.php; or a (4) project or (5) category name to printallbugpageword.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3303?
CVE-2010-3303 is classified as a moderate severity vulnerability due to its potential impact on user data integrity.
How do I fix CVE-2010-3303?
To fix CVE-2010-3303, upgrade MantisBT to version 1.2.3 or later to eliminate the cross-site scripting vulnerabilities.
Who is affected by CVE-2010-3303?
CVE-2010-3303 affects MantisBT versions prior to 1.2.3, including 0.18.0 to 1.0.2.
What types of attacks does CVE-2010-3303 enable?
CVE-2010-3303 enables remote authenticated administrators to conduct cross-site scripting (XSS) attacks.
Is there a workaround for CVE-2010-3303?
There are no known effective workarounds for CVE-2010-3303; upgrading is the recommended approach.