An XSS vulnerability was discovered, affecting MantisBT Custom fields management pages. It is caused by unescaped output of 'return URL' GPC parameter. Upstream bug: https://mantisbt.org/bugs/view.php?id=20956 Upstream fixes: https://github.com/mantisbt/mantisbt/commit/11ab3d6c82a1d3a89b1024f77349fb60a83743c5 https://github.com/mantisbt/mantisbt/commit/5068df2dcf79c34741c746c9b27e0083f2a374da References: http://seclists.org/oss-sec/2016/q2/523
Created mantis tracking bugs for this issue: Affects: fedora-all [bug 1345785] Affects: epel-5 [bug 1345786]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.