CVE-2013-1934: XSS
A cross-site scripting (XSS) vulnerability in the configuration report page (admconfigreport.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2013-1934?
CVE-2013-1934 is a cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14.
How does CVE-2013-1934 affect MantisBT?
CVE-2013-1934 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.
What is the severity level of CVE-2013-1934?
The severity level of CVE-2013-1934 is medium with a severity score of 5.4.
Which software versions are affected by CVE-2013-1934?
MantisBT versions 1.2.0rc1 before 1.2.14 are affected by CVE-2013-1934.
Are there any references for CVE-2013-1934?
Yes, you can find references for CVE-2013-1934 at the following links: [Debian Security Advisory DSA-3120](http://www.debian.org/security/2015/dsa-3120), [oss-security mailing list](http://www.openwall.com/lists/oss-security/2013/04/09/1), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1934).