Bug 1477526 (CVE-2017-12062)

Summary: CVE-2017-12062 mantis: XSS in manage_user_page.php
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: giallu
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: mantis 2.5.2 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-21 11:55:16 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Adam Mariš 2017-08-02 10:33:49 UTC
An XSS issue was discovered in manage_user_page.php in MantisBT 2.x
before 2.5.2. The 'filter' field is not sanitized before being rendered
in the Manage User page, allowing remote attackers to execute arbitrary
JavaScript code if CSP is disabled.

Affected versions: 2.1.0 through 2.5.1

Upstream bug:

https://mantisbt.org/bugs/view.php?id=23166

Upstream fix:

https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7

References:

http://openwall.com/lists/oss-security/2017/08/01/1