CVE-2020-8981: XSS
A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repodelete.php Delete Repository page allows execution of arbitrary code via a repo name (if CSP settings permit it). This is related to CVE-2018-16362.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-8981?
CVE-2020-8981 is a cross-site scripting (XSS) vulnerability in the Source Integration plugin for MantisBT.
What is the severity of CVE-2020-8981?
CVE-2020-8981 has a severity rating of 6.1 (medium).
How does CVE-2020-8981 affect MantisBT?
CVE-2020-8981 affects MantisBT versions 1.6.2 and earlier in the Source Integration plugin.
How can the CVE-2020-8981 vulnerability be exploited?
The CVE-2020-8981 vulnerability can be exploited through the repo_delete.php Delete Repository page by executing arbitrary code via a repository name.
How can I fix CVE-2020-8981?
To fix CVE-2020-8981, upgrade the Source Integration plugin for MantisBT to version 1.6.2 or 2.3.1 or later.