CVE-2014-9269: XSS
Cross-site scripting (XSS) vulnerability in helperapi.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9269?
CVE-2014-9269 has been rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-9269?
To mitigate CVE-2014-9269, upgrade MantisBT to version 1.2.18 or later, where the vulnerability has been patched.
What does CVE-2014-9269 exploit?
CVE-2014-9269 exploits a cross-site scripting vulnerability in MantisBT's helper_api.php when the Extended project browser is enabled.
Which versions of MantisBT are affected by CVE-2014-9269?
CVE-2014-9269 affects MantisBT versions from 1.1.0a1 through 1.2.x prior to 1.2.18.
Can CVE-2014-9269 be exploited remotely?
Yes, CVE-2014-9269 can be exploited remotely by attackers using crafted project cookies to inject malicious scripts.