A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name. References: https://mantisbt.org/blog/archives/mantisbt/613 https://mantisbt.org/bugs/view.php?id=24814
Created mantis tracking bugs for this issue: Affects: fedora-all [bug 1646588]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.