CVE-2014-8987: XSS
Published Aug 24, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (admconfigreport.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via the configoption parameter, a different vulnerability than CVE-2014-8986.
Affected Software
5 affected components
MantisBT mantisbt=1.2.13
MantisBT mantisbt=1.2.14
MantisBT mantisbt=1.2.15
MantisBT mantisbt=1.2.16
MantisBT mantisbt=1.2.17
Event History
Aug 24, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8987?
CVE-2014-8987 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2014-8987?
To fix CVE-2014-8987, upgrade MantisBT to version 1.2.18 or later.
3
Which versions of MantisBT are affected by CVE-2014-8987?
CVE-2014-8987 affects MantisBT versions 1.2.13 through 1.2.17.
4
What type of vulnerability is CVE-2014-8987?
CVE-2014-8987 is a cross-site scripting (XSS) vulnerability that allows remote code injection.
5
Can CVE-2014-8987 be exploited by non-administrators?
No, exploitation of CVE-2014-8987 requires remote administrator access to the configuration report page.