Cross-site scripting in MantisBT - CVE-2014-8987
Published: August 24, 2015 / Updated: January 3, 2021
MantisBT
mantisbt.sourceforge.net
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. The vulnerability allows remote administrators to inject arbitrary web script or HTML via the config_option parameter, a different vulnerability than CVE-2014-8986.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
External links
- http://www.mantisbt.org/bugs/view.php?id=17870
- http://www.openwall.com/lists/oss-security/2014/11/14/9
- http://www.openwall.com/lists/oss-security/2014/11/15/2
- http://www.openwall.com/lists/oss-security/2014/11/15/3
- http://www.openwall.com/lists/oss-security/2014/11/15/4
- http://www.openwall.com/lists/oss-security/2014/11/19/21
- https://github.com/mantisbt/mantisbt/commit/49c3d089