CVE-2017-6797: XSS
Published Mar 10, 2017
·Updated
A cross-site scripting (XSS) vulnerability in bugchangestatuspage.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'actiontype' parameter.
Affected Software
2 affected components
MantisBT mantisbt<1.3.7
MantisBT mantisbt>=2.0.0<2.2.1
Remediation
Patch Available
Event History
Mar 10, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6797?
CVE-2017-6797 is classified as a medium-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-6797?
To fix CVE-2017-6797, upgrade MantisBT to version 1.3.7 or to version 2.2.1 or later.
3
What types of attacks can CVE-2017-6797 facilitate?
CVE-2017-6797 can facilitate cross-site scripting (XSS) attacks that allow remote attackers to inject arbitrary JavaScript.
4
What is the affected software range for CVE-2017-6797?
CVE-2017-6797 affects MantisBT versions prior to 1.3.7 and 2.x versions prior to 2.2.1.
5
Who is primarily impacted by CVE-2017-6797?
Users of MantisBT who are running affected versions are primarily impacted by CVE-2017-6797.