First published: Fri Mar 10 2017(Updated: )
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Libreport-plugin-mantisbt | <1.3.7 | |
CentOS Libreport-plugin-mantisbt | >=2.0.0<2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6797 is classified as a medium-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2017-6797, upgrade MantisBT to version 1.3.7 or to version 2.2.1 or later.
CVE-2017-6797 can facilitate cross-site scripting (XSS) attacks that allow remote attackers to inject arbitrary JavaScript.
CVE-2017-6797 affects MantisBT versions prior to 1.3.7 and 2.x versions prior to 2.2.1.
Users of MantisBT who are running affected versions are primarily impacted by CVE-2017-6797.