CVE-2019-15074: XSS
The Timeline feature in myviewpage.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15074?
The severity of CVE-2019-15074 is critical, with a severity value of 9.6.
How does CVE-2019-15074 affect MantisBT?
CVE-2019-15074 affects MantisBT versions 2.13.0 through 2.21.1.
What is the vulnerability type of CVE-2019-15074?
CVE-2019-15074 is a stored cross-site scripting (XSS) vulnerability.
What can an attacker do with CVE-2019-15074?
An attacker can execute arbitrary code after uploading an attachment with a crafted filename.
Are there any fixes available for CVE-2019-15074?
Yes, fixes for CVE-2019-15074 are available in the MantisBT commit: https://github.com/mantisbt/mantisbt/commit/9cee1971c498bbe0a72bca1c773fae50171d8c27