An XSS vulnerability was discovered in MantisBT's Filter API, affecting the View Issues page. It is caused by unescaped output of the 'view_type' GPC parameter References: http://seclists.org/oss-sec/2016/q3/306 Upstream bug: https://mantisbt.org/bugs/view.php?id=21611 Upstream patch: https://github.com/mantisbt/mantisbt/commit/7086c2d8
Created mantis tracking bugs for this issue: Affects: fedora-all [bug 1368091] Affects: epel-5 [bug 1368092]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.