CVE-2010-4348: XSS
Cross-site scripting (XSS) vulnerability in admin/upgradeunattended.php in MantisBT before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the dbtype parameter, related to an unsafe call by MantisBT to a function in the ADOdb Library for PHP.
Other sources
The MantisBT project was notified by Gjoko Krstic of Zero Science Lab (gjoko) of multiple vulnerabilities affecting MantisBT <1.2.4.
The two following advisories have been released explaining the vulnerabilities in greater detail:
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4983.php http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4984.php
As one of these vulnerabilities allows the reading of arbitrary files from the file system we are treating this issue with critical severity. Please note that this issue only affects users who have not removed the "admin" directory from their MantisBT installation. We recommend, instruct and warn users to remove this directory after installation however it is clear that many users ignore these warnings.
I have requested CVE numbers via oss-sec (awaiting list moderation).
As Redhat is using MantisBT 1.1.x you will need to apply the following patch to resolve the issue in this older version of MantisBT: http://git.mantisbt.org/?p=mantisbt.git;a=commitdiffplain;h=2641fdc60d2032ae1586338d6416e1eadabd7590
We have also released MantisBT 1.2.4 which resolves the issue for users of our stable 1.2.x branch.
The bug report tracking this issue upstream at MantisBT: http://www.mantisbt.org/bugs/view.php?id=12607
If there are any questions or concerns please feel free to contact me.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4348?
CVE-2010-4348 has been classified as a moderate severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2010-4348?
To fix CVE-2010-4348, update MantisBT to version 1.2.4 or later, which addresses this vulnerability.
What software versions are affected by CVE-2010-4348?
CVE-2010-4348 affects multiple versions of MantisBT including 0.18.0 to 1.2.3, along with several release candidates.
What type of vulnerability is CVE-2010-4348?
CVE-2010-4348 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
Can CVE-2010-4348 lead to data compromise?
Yes, exploitation of CVE-2010-4348 could potentially lead to unauthorized access to sensitive user data.