First published: Thu Feb 13 2020(Updated: )
A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_delete.php Delete Repository page allows execution of arbitrary code via a repo name (if CSP settings permit it). This is related to CVE-2018-16362.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Source Integration | <1.6.2 | |
Mantisbt Source Integration | >=2.0.0<2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8981 is a cross-site scripting (XSS) vulnerability in the Source Integration plugin for MantisBT.
CVE-2020-8981 has a severity rating of 6.1 (medium).
CVE-2020-8981 affects MantisBT versions 1.6.2 and earlier in the Source Integration plugin.
The CVE-2020-8981 vulnerability can be exploited through the repo_delete.php Delete Repository page by executing arbitrary code via a repository name.
To fix CVE-2020-8981, upgrade the Source Integration plugin for MantisBT to version 1.6.2 or 2.3.1 or later.