Show filters
120 Total Results
Displaying 31-40 of 120
Sort by:
Attacker Value
Unknown
CVE-2013-1932
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via a project name.
0
Attacker Value
Unknown
CVE-2013-1930
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.
0
Attacker Value
Unknown
CVE-2013-1931
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.
0
Attacker Value
Unknown
CVE-2019-15715
Disclosure Date: October 09, 2019 (last updated November 27, 2024)
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
0
Attacker Value
Unknown
CVE-2019-15074
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed.
0
Attacker Value
Unknown
CVE-2018-16514
Disclosure Date: June 20, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-13055.
0
Attacker Value
Unknown
CVE-2018-9839
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying the 'm_id' parameter), any user with REPORTER access or above is able to view any private issue's details (summary, description, steps to reproduce, additional information) when cloning it. By checking the 'Copy issue notes' and 'Copy attachments' checkboxes and completing the clone operation, this data also becomes public (except private notes).
0
Attacker Value
Unknown
CVE-2018-17783
Disclosure Date: October 30, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.
0
Attacker Value
Unknown
CVE-2018-17782
Disclosure Date: October 30, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.
0
Attacker Value
Unknown
CVE-2018-16362
Disclosure Date: September 02, 2018 (last updated November 27, 2024)
An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site scripting (XSS) vulnerability in the Manage Repository and Changesets List pages allows execution of arbitrary code (if CSP settings permit it) via repo_manage_page.php or list.php.
0