Bug 1431179 (CVE-2017-6797) - CVE-2017-6797 mantis: Cross site scripting in bug_change_status_page.php
Summary: CVE-2017-6797 mantis: Cross site scripting in bug_change_status_page.php
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2017-6797
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1431180 1431181
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-03-10 14:26 UTC by Andrej Nemec
Modified: 2019-09-29 14:08 UTC (History)
1 user (show)

Fixed In Version: mantis 1.3.7
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-03-13 09:11:55 UTC
Embargoed:


Attachments (Terms of Use)

Description Andrej Nemec 2017-03-10 14:26:45 UTC
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter. 

Upstream bug:

http://www.mantisbt.org/bugs/view.php?id=22486

Upstream patches:

https://github.com/mantisbt/mantisbt/commit/a2d90ecabf3bcf3aa22ed9dbbecfd3d37902956f
https://github.com/mantisbt/mantisbt/commit/c272c3f65da9677e505ff692b1f1e476b3afa56e

Comment 1 Andrej Nemec 2017-03-10 14:27:30 UTC
Created mantis tracking bugs for this issue:

Affects: epel-5 [bug 1431181]
Affects: fedora-all [bug 1431180]

Comment 2 Gianluca Sforna 2017-03-12 10:24:29 UTC
So, according to the upstream bug discussion, the bug was introduced during 1.3.x development. e.g. 1.2.x is NOT affected.

http://www.mantisbt.org/bugs/view.php?id=22486#c55996


Note You need to log in before you can comment on or make changes to this bug.