CVE-2013-0197: XSS
Cross-site scripting (XSS) vulnerability in the filterdrawselectionarea2 function in core/filterapi.php in MantisBT 1.2.12 before 1.2.13 allows remote attackers to inject arbitrary web script or HTML via the matchtype parameter to bugs/search.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0197?
The severity of CVE-2013-0197 is classified as high due to its potential for remote code execution through cross-site scripting.
How do I fix CVE-2013-0197?
To fix CVE-2013-0197, upgrade MantisBT to version 1.2.13 or later, which contains the necessary patches.
What systems are affected by CVE-2013-0197?
CVE-2013-0197 affects MantisBT versions 1.2.12 and before; version 1.2.13 and later are not vulnerable.
What type of vulnerability is CVE-2013-0197?
CVE-2013-0197 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts.
Can CVE-2013-0197 be exploited without user interaction?
Yes, CVE-2013-0197 can be exploited by an attacker without requiring user interaction, making it especially dangerous.