CVE-2014-8986: XSS
Cross-site scripting (XSS) vulnerability in the selection list in the filters in the Configuration Report page (admconfigreport.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via a crafted config option, a different vulnerability than CVE-2014-8987.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8986?
CVE-2014-8986 is considered to be of medium severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-8986?
To fix CVE-2014-8986, update MantisBT to version 1.2.18 or later to mitigate the vulnerability.
What versions of MantisBT are affected by CVE-2014-8986?
CVE-2014-8986 affects MantisBT versions 1.2.13 through 1.2.17.
Who can exploit CVE-2014-8986?
CVE-2014-8986 can be exploited by remote administrators who can inject arbitrary web scripts or HTML.
What kind of attacks can CVE-2014-8986 lead to?
CVE-2014-8986 can lead to cross-site scripting (XSS) attacks, allowing unauthorized actions in a user's session.