First published: Thu May 15 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the filter_draw_selection_area2 function in core/filter_api.php in MantisBT 1.2.12 before 1.2.13 allows remote attackers to inject arbitrary web script or HTML via the match_type parameter to bugs/search.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Libreport-plugin-mantisbt | =1.2.12 | |
CentOS Libreport-plugin-mantisbt | =1.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-0197 is classified as high due to its potential for remote code execution through cross-site scripting.
To fix CVE-2013-0197, upgrade MantisBT to version 1.2.13 or later, which contains the necessary patches.
CVE-2013-0197 affects MantisBT versions 1.2.12 and before; version 1.2.13 and later are not vulnerable.
CVE-2013-0197 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts.
Yes, CVE-2013-0197 can be exploited by an attacker without requiring user interaction, making it especially dangerous.