CVE-2011-2938: XSS
Multiple cross-site scripting (XSS) vulnerabilities in filterapi.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script or HTML via a parameter, as demonstrated by the projectid parameter to search.php.
Other sources
Original vulnerability report by Net.Edit0r (Net.Edit0r) from BlACK Hat Group [http://black-hg.org] is available at: http://packetstormsecurity.org/files/104149
MantisBT bug report for full details of the issue: http://www.mantisbt.org/bugs/view.php?id=13245
Please note that the second SQL injection vulnerability identified by Net.Edit0r is not reproducible (refer to the MantisBT bug report above for reasons why).
A patch for 1.2.6 is available at: https://github.com/mantisbt/mantisbt/commit/317f3db3a3c68775de3acf3b15f55b1e3c18f93b
MantisBT 1.2.7 is currently being packaged and will be available shortly through usual channels.
A CVE request and notice has been sent to oss-security.com
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2938?
CVE-2011-2938 is classified as a high severity vulnerability due to the potential for remote code execution via cross-site scripting.
How do I fix CVE-2011-2938?
To fix CVE-2011-2938, upgrade to MantisBT version 1.2.7 or later.
What versions of MantisBT are affected by CVE-2011-2938?
Affected versions of MantisBT include all versions prior to 1.2.7, specifically up to 1.2.6 and earlier.
What type of vulnerability is CVE-2011-2938?
CVE-2011-2938 is a cross-site scripting (XSS) vulnerability.
Can CVE-2011-2938 allow unauthorized access to my MantisBT installation?
Yes, CVE-2011-2938 can potentially allow unauthorized attackers to inject scripts, compromising your MantisBT installation.