CVE-2019-15539: XSS
Published Mar 19, 2020
·Updated
The projdoceditpage.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed when editing the document's page.
Affected Software
2 affected componentsFixes available
MantisBT mantisbt<2.21.3
composer/mantisbt/mantisbt<2.21.3
2.21.3
Remediation
Event History
Mar 19, 2020
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:11 PM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-15539.
2
What is the severity rating of CVE-2019-15539?
CVE-2019-15539 has a severity rating of medium (6.1).
3
What is the affected software for CVE-2019-15539?
The affected software for CVE-2019-15539 is MantisBT version up to exclusive 2.21.3.
4
What is the CWE classification for CVE-2019-15539?
CVE-2019-15539 is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation).
5
How can I fix the CVE-2019-15539 vulnerability?
To fix the CVE-2019-15539 vulnerability, you should update MantisBT to version 2.21.3 or later.