CVE-2018-14504: XSS
An issue was discovered in managefiltereditpage.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with a crafted name (e.g., 'foobar" onclick="alert(1)').
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-14504?
CVE-2018-14504 is a vulnerability discovered in MantisBT 2.x through 2.15.0 that allows for cross-site scripting (XSS) attacks.
How severe is CVE-2018-14504?
CVE-2018-14504 has a severity level of medium, with a CVSS score of 6.1.
How does CVE-2018-14504 affect MantisBT?
CVE-2018-14504 affects MantisBT versions 2.x through 2.15.0.
What is the impact of CVE-2018-14504?
CVE-2018-14504 allows for the execution of arbitrary code in the context of a user's session on MantisBT.
How can CVE-2018-14504 be fixed?
To fix CVE-2018-14504, users should update to a version of MantisBT that is not affected by the vulnerability.