First published: Fri Aug 03 2018(Updated: )
An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with a crafted name (e.g., 'foobar" onclick="alert(1)').
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | >=2.0.0<=2.15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14504 is a vulnerability discovered in MantisBT 2.x through 2.15.0 that allows for cross-site scripting (XSS) attacks.
CVE-2018-14504 has a severity level of medium, with a CVSS score of 6.1.
CVE-2018-14504 affects MantisBT versions 2.x through 2.15.0.
CVE-2018-14504 allows for the execution of arbitrary code in the context of a user's session on MantisBT.
To fix CVE-2018-14504, users should update to a version of MantisBT that is not affected by the vulnerability.