CVE-2014-9270: XSS
Cross-site scripting (XSS) vulnerability in the projaxarrayserializeforautocomplete function in core/projaxapi.php in MantisBT 1.1.0a3 through 1.2.17 allows remote attackers to inject arbitrary web script or HTML via the "profile/Platform" field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9270?
CVE-2014-9270 has a moderate severity level due to the presence of cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2014-9270?
To fix CVE-2014-9270, you should upgrade MantisBT to a version that has patched the vulnerability, such as 1.2.18 or later.
What versions of MantisBT are affected by CVE-2014-9270?
CVE-2014-9270 affects MantisBT versions 1.1.0a3 through 1.2.17.
Can CVE-2014-9270 be exploited remotely?
Yes, CVE-2014-9270 can be exploited remotely by attackers to inject arbitrary web script or HTML.
What are the potential impacts of CVE-2014-9270?
The potential impacts of CVE-2014-9270 include data theft, session hijacking, or unauthorized actions on behalf of a user.