Description
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-6154 | MantisBT allows cross-site scripting (XSS) via crafted filename |
Github GHSA |
GHSA-gg4j-279j-22ph | MantisBT allows cross-site scripting (XSS) via crafted filename |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T00:34:53.243Z
Reserved: 2019-08-15T00:00:00.000Z
Link: CVE-2019-15074
No data.
Status : Modified
Published: 2019-08-21T19:15:13.920
Modified: 2026-06-17T02:19:39.197
Link: CVE-2019-15074
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA