CVE-2014-9271: XSS
Cross-site scripting (XSS) vulnerability in filedownload.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to inline attachments, as demonstrated by a .swf.jpeg filename.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9271?
CVE-2014-9271 has a medium severity level due to the potential for cross-site scripting attacks.
How do I fix CVE-2014-9271?
To fix CVE-2014-9271, upgrade MantisBT to version 1.2.18 or later to eliminate the vulnerability.
Who is affected by CVE-2014-9271?
CVE-2014-9271 affects users of MantisBT versions prior to 1.2.18 and certain Debian Linux 7.0 implementations.
What type of vulnerability is represented by CVE-2014-9271?
CVE-2014-9271 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2014-9271 be exploited remotely?
Yes, CVE-2014-9271 can be exploited remotely by authenticated users to inject arbitrary web scripts.