Common Vulnerabilities and Exposures assigned an identifier CVE-2010-3763 to the following vulnerability: Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303. References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3763 [2] http://www.openwall.com/lists/oss-security/2010/09/14/12 [3] http://www.openwall.com/lists/oss-security/2010/09/14/13 [4] http://www.mantisbt.org/bugs/changelog_page.php?version_id=111 [5] http://www.mantisbt.org/bugs/view.php?id=12309 Proposed patch from the reporter: [6] http://www.mantisbt.org/bugs/file_download.php?file_id=3017&type=bug
The above listed patch [6] seems to be applicable to current versions of the mantis package, as shipped with Fedora release of 12 and 13. Please fix.
This was fixed in mantis 1.1.8-5 Not sure why it was not closed automatically