First published: Mon Aug 24 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via the config_option parameter, a different vulnerability than CVE-2014-8986.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Libreport-plugin-mantisbt | =1.2.13 | |
CentOS Libreport-plugin-mantisbt | =1.2.14 | |
CentOS Libreport-plugin-mantisbt | =1.2.15 | |
CentOS Libreport-plugin-mantisbt | =1.2.16 | |
CentOS Libreport-plugin-mantisbt | =1.2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8987 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2014-8987, upgrade MantisBT to version 1.2.18 or later.
CVE-2014-8987 affects MantisBT versions 1.2.13 through 1.2.17.
CVE-2014-8987 is a cross-site scripting (XSS) vulnerability that allows remote code injection.
No, exploitation of CVE-2014-8987 requires remote administrator access to the configuration report page.