CVE-2018-13055: XSS
Published Aug 3, 2018
·Updated
A cross-site scripting (XSS) vulnerability in the View Filters page (viewfilterspage.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATHINFO.
Affected Software
2 affected componentsFixes available
MantisBT mantisbt>=2.1.0<=2.15.0
composer/mantisbt/mantisbt>=2.1.0<2.15.1
2.15.1
Remediation
Patch Available
Event History
Aug 3, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:57 AM
Data Sourced
via GitHub·02:57 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-13055?
CVE-2018-13055 is a cross-site scripting (XSS) vulnerability in MantisBT versions 2.1.0 through 2.15.0.
2
How does CVE-2018-13055 affect MantisBT?
CVE-2018-13055 allows remote attackers to inject arbitrary code through a crafted PATH_INFO on the View Filters page in MantisBT.
3
How severe is CVE-2018-13055?
CVE-2018-13055 has a severity rating of 6.1 (medium).
4
How can I fix CVE-2018-13055?
To fix CVE-2018-13055, upgrade your MantisBT installation to version 2.15.1 or later.
5
Where can I find more information about CVE-2018-13055?
You can find more information about CVE-2018-13055 in the MantisBT blog post and the official MantisBT bug report.