CVE-2019-15539
- EPSS 0.52%
- Veröffentlicht 19.03.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:57
The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted fi...
CVE-2009-2802
- EPSS 0.38%
- Veröffentlicht 09.11.2019 03:15:10
- Zuletzt bearbeitet 21.11.2024 01:05:46
MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks.
CVE-2013-1811
- EPSS 0.31%
- Veröffentlicht 07.11.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 01:50:26
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
CVE-2013-1930
- EPSS 0.67%
- Veröffentlicht 31.10.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:50:41
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.
CVE-2013-1931
- EPSS 1.43%
- Veröffentlicht 31.10.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:50:42
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.
CVE-2013-1932
- EPSS 0.69%
- Veröffentlicht 31.10.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:50:42
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via a project name.
CVE-2013-1934
- EPSS 0.35%
- Veröffentlicht 31.10.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:50:42
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.
CVE-2019-15715
- EPSS 21.33%
- Veröffentlicht 09.10.2019 20:15:23
- Zuletzt bearbeitet 21.11.2024 04:29:18
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
CVE-2019-15074
- EPSS 0.75%
- Veröffentlicht 21.08.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:28:00
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The cod...
CVE-2018-16514
- EPSS 0.25%
- Veröffentlicht 20.06.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 03:52:53
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit i...