First published: Fri Mar 10 2017(Updated: )
A cross-site scripting (XSS) vulnerability in view_filters_page.php in MantisBT before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'view_type' parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Libreport-plugin-mantisbt | <=2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6799 has been rated as a medium severity cross-site scripting vulnerability.
To resolve CVE-2017-6799, upgrade MantisBT to version 2.2.1 or later.
CVE-2017-6799 affects the view_filters_page.php component of MantisBT before version 2.2.1.
Yes, CVE-2017-6799 can allow unauthorized attackers to inject arbitrary JavaScript code.
The 'view_type' parameter is exploited in CVE-2017-6799 to carry out the cross-site scripting attack.