An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled.
References
Link Resource
http://openwall.com/lists/oss-security/2017/08/01/1 Mailing List Third Party Advisory
http://openwall.com/lists/oss-security/2017/08/01/2 Mailing List Third Party Advisory
http://www.securitytracker.com/id/1039030 Third Party Advisory VDB Entry
https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7 Patch Third Party Advisory
https://mantisbt.org/bugs/view.php?id=23166 Exploit Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-08-01T15:00:00

Updated: 2017-08-02T09:57:01

Reserved: 2017-07-31T00:00:00


Link: CVE-2017-12062

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-08-01T15:29:00.593

Modified: 2017-08-15T17:17:01.677


Link: CVE-2017-12062

JSON object: View

cve-icon Redhat Information

No data.

CWE