First published: Thu Oct 31 2019(Updated: )
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | =1.2.14 | |
Fedoraproject Fedora | =17 | |
Fedoraproject Fedora | =18 | |
debian/mantis |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1931 is a cross-site scripting (XSS) vulnerability in MantisBT 1.2.14.
CVE-2013-1931 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.
CVE-2013-1931 has a severity rating of 6.1, which is considered medium.
Updating MantisBT to version 1.2.15 or later will fix CVE-2013-1931.
Yes, you can find additional references for CVE-2013-1931 at the following links: [link1](http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103438.html) and [link2](http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103459.html), as well as [link3](http://www.openwall.com/lists/oss-security/2013/04/06/4).