Description
Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup.php, (3) action parameter to login_select_proj_page.php, or (4) hide_status parameter to view_all_set.php.
Product(s):
- Mantis 0.10.1
- Mantis 0.10.2
- Mantis 0.10
- Mantis 0.11.1
- Mantis 0.11
- Mantis 0.12
- Mantis 0.13.1
- Mantis 0.13
- Mantis 0.14.1
- Mantis 0.14.2
- Mantis 0.14.3
- Mantis 0.14.4
- Mantis 0.14.5
- Mantis 0.14.6
- Mantis 0.14.7
- Mantis 0.14.8
- Mantis 0.14
- Mantis 0.15.10
- Mantis 0.15.11
- Mantis 0.15.12
- Mantis 0.15.1
- Mantis 0.15.2
- Mantis 0.15.3
- Mantis 0.15.4
- Mantis 0.15.5
- Mantis 0.15.6
- Mantis 0.15.7
- Mantis 0.15.8
- Mantis 0.15.9
- Mantis 0.15
- Mantis 0.16.0
- Mantis 0.16.1
- Mantis 0.16
- Mantis 0.17.0
- Mantis 0.17.1
- Mantis 0.17.2
- Mantis 0.17.3
- Mantis 0.17.4
- Mantis 0.17.4a
- Mantis 0.17.5
- Mantis 0.17
- Mantis 0.18.0 RC1
- Mantis 0.18.0a2
- Mantis 0.18.0a3
- Mantis 0.18.0a4
- Mantis 0.18
- Mantis 0.18a1
- Mantis 0.19.0a
- Mantis 0.9.1
- Mantis 0.9
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2004-1730, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2004-1730 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.