CVE-2017-6799: XSS
Published Mar 10, 2017
·Updated
A cross-site scripting (XSS) vulnerability in viewfilterspage.php in MantisBT before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'viewtype' parameter.
Affected Software
1 affected component
MantisBT mantisbt<=2.2.0
Remediation
Patch Available
Event History
Mar 10, 2017
CVE Published
via MITRE·10:29 AM
Data Sourced
via MITRE·10:29 AM
Description
Data Sourced
via NVD·10:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6799?
CVE-2017-6799 has been rated as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2017-6799?
To resolve CVE-2017-6799, upgrade MantisBT to version 2.2.1 or later.
3
What specific component is affected by CVE-2017-6799?
CVE-2017-6799 affects the view_filters_page.php component of MantisBT before version 2.2.1.
4
Can CVE-2017-6799 allow unauthorized access?
Yes, CVE-2017-6799 can allow unauthorized attackers to inject arbitrary JavaScript code.
5
What input parameter is exploited in CVE-2017-6799?
The 'view_type' parameter is exploited in CVE-2017-6799 to carry out the cross-site scripting attack.