The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1, cross-site scripting in the MantisBT LinkedCustomFields plugin allows Javascript execution, when a crafted Custom Field is linked via the plugin and displayed when reporting a new Issue or editing an existing one. This issue is fixed in version 2.0.1. As a workaround, one may utilize MantisBT's default Content Security Policy, which blocks script execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-53714 The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1, cross-site scripting in the MantisBT LinkedCustomFields plugin allows Javascript execution, when a crafted Custom Field is linked via the plugin and displayed when reporting a new Issue or editing an existing one. This issue is fixed in version 2.0.1. As a workaround, one may utilize MantisBT's default Content Security Policy, which blocks script execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-28T15:12:57.432Z

Reserved: 2023-11-30T13:39:50.864Z

Link: CVE-2023-49802

cve-icon Vulnrichment

Updated: 2024-08-02T22:01:26.034Z

cve-icon NVD

Status : Modified

Published: 2023-12-11T22:15:06.730

Modified: 2024-11-21T08:33:52.427

Link: CVE-2023-49802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.