CVE-2013-1932: XSS
Published Oct 31, 2019
·Updated
A cross-site scripting (XSS) vulnerability in the configuration report page (admconfigreport.php) in MantisBT 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via a project name.
Affected Software
2 affected components
debian/mantis
MantisBT mantisbt=1.2.13
Event History
Oct 31, 2019
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2013-1932?
CVE-2013-1932 is a cross-site scripting (XSS) vulnerability in MantisBT 1.2.13.
2
How does CVE-2013-1932 affect MantisBT?
CVE-2013-1932 allows remote authenticated users to inject arbitrary web script or HTML via a project name.
3
What is the severity of CVE-2013-1932?
The severity of CVE-2013-1932 is medium with a CVSS score of 5.4.
4
How can I fix CVE-2013-1932 in MantisBT 1.2.13?
There is no known remedy for CVE-2013-1932 in MantisBT 1.2.13.
5
Where can I find more information about CVE-2013-1932?
You can find more information about CVE-2013-1932 in the following references: [1] [2] [3].