CVE-2016-5364: XSS
Published Feb 17, 2017
·Updated
Cross-site scripting (XSS) vulnerability in managecustomfieldeditpage.php in MantisBT 1.2.19 and earlier allows remote attackers to inject arbitrary web script or HTML via the return parameter.
Affected Software
1 affected component
MantisBT mantisbt<=1.2.19
Remediation
Patch Available
Patch Available
Event History
Feb 17, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5364?
CVE-2016-5364 has a medium severity rating due to its potential for cross-site scripting attacks.
2
What software versions are affected by CVE-2016-5364?
MantisBT versions up to and including 1.2.19 are affected by CVE-2016-5364.
3
How do I fix CVE-2016-5364?
To fix CVE-2016-5364, upgrade MantisBT to a version newer than 1.2.19 where the issue has been addressed.
4
What type of vulnerability is CVE-2016-5364?
CVE-2016-5364 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts.
5
What impact does CVE-2016-5364 have on web applications?
CVE-2016-5364 can allow attackers to execute malicious scripts in the context of a user's session, compromising their data and interactions.