CVE-2014-9272: XSS
The stringinserthref function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9272?
CVE-2014-9272 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
Which versions are affected by CVE-2014-9272?
CVE-2014-9272 affects MantisBT versions 1.2.0a1 through 1.2.17, including various earlier releases.
How do I fix CVE-2014-9272?
To fix CVE-2014-9272, update MantisBT to version 1.2.18 or later, where the vulnerability is addressed.
What types of attacks can CVE-2014-9272 enable?
CVE-2014-9272 allows attackers to execute cross-site scripting (XSS) attacks by improperly validating URL protocols.
How does CVE-2014-9272 affect user security?
CVE-2014-9272 compromises user security by allowing malicious scripts to be executed in the context of a user's browser.