Description
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-6154 | MantisBT allows cross-site scripting (XSS) via crafted filename |
Github GHSA |
GHSA-gg4j-279j-22ph | MantisBT allows cross-site scripting (XSS) via crafted filename |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T00:34:53.243Z
Reserved: 2019-08-15T00:00:00.000Z
Link: CVE-2019-15074
No data.
Status : Modified
Published: 2019-08-21T19:15:13.920
Modified: 2024-11-21T04:28:00.020
Link: CVE-2019-15074
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA