VulnerabilityModified
CVE-2017-12062
An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2.
MEDIUM 6.1EPSS 3.90%
Does this matter?
Lower severity and a low EPSS score (3.90%). Track it; it rarely justifies an emergency change on its own.
Description
An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 3.90% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mantisbt/mantisbt
- Source
- cve@mitre.org
References
- http://openwall.com/lists/oss-security/2017/08/01/1Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2017/08/01/2Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1039030Third Party Advisory, VDB Entry
- https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7Patch, Third Party Advisory
- https://mantisbt.org/bugs/view.php?id=23166Exploit, Issue Tracking, Vendor Advisory
- http://openwall.com/lists/oss-security/2017/08/01/1Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2017/08/01/2Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1039030Third Party Advisory, VDB Entry
- https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7Patch, Third Party Advisory
- https://mantisbt.org/bugs/view.php?id=23166Exploit, Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.