CVE-2017-7241
Last modified
CVE-2017-7241 is a vulnerability of currently unknown severity. A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this vulnerability is not exploitable if the admin tools directory is removed, as recommended in the "Post-installation and upgrade tasks" of the MantisBT Admin Guide. A reminder to do so is also displayed on the login page.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Mantisbt | Mantisbt | 1.2.16 | — |
| Mantisbt | Mantisbt | 1.2.17 | — |
| Mantisbt | Mantisbt | 1.2.18 | — |
| Mantisbt | Mantisbt | 1.2.19 | — |
| Mantisbt | Mantisbt | 1.2.20 | — |
| Mantisbt | Mantisbt | 1.3.0 | Beta1 |
| Mantisbt | Mantisbt | 1.3.1 | — |
| Mantisbt | Mantisbt | 1.3.2 | — |
| Mantisbt | Mantisbt | 1.3.3 | — |
| Mantisbt | Mantisbt | 1.3.4 | — |
| Mantisbt | Mantisbt | 1.3.5 | — |
| Mantisbt | Mantisbt | 1.3.6 | — |
| Mantisbt | Mantisbt | 1.3.7 | — |
| Mantisbt | Mantisbt | 1.3.8 | — |
| Mantisbt | Mantisbt | 1.3.9 | — |
| Mantisbt | Mantisbt | 2.0.0 | — |
| Mantisbt | Mantisbt | 2.0.1 | — |
| Mantisbt | Mantisbt | 2.1.0 | — |
| Mantisbt | Mantisbt | 2.1.1 | — |
| Mantisbt | Mantisbt | 2.1.2 | — |
| Mantisbt | Mantisbt | 2.1.3 | — |
| Mantisbt | Mantisbt | 2.2.0 | — |
| Mantisbt | Mantisbt | 2.2.1 | — |
| Mantisbt | Mantisbt | 2.2.2 | — |
| Mantisbt | Mantisbt | 2.2.3 | — |
| Mantisbt | Mantisbt | 2.3.0 | — |
References
- http://openwall.com/lists/oss-security/2017/03/30/4Mailing List, Third Party Advisory
- http://www.mantisbt.org/bugs/view.php?id=22568Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/97253Third Party Advisory, VDB Entry
- http://openwall.com/lists/oss-security/2017/03/30/4Mailing List, Third Party Advisory
- http://www.mantisbt.org/bugs/view.php?id=22568Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/97253Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7241?
How severe is CVE-2017-7241?
How do I fix CVE-2017-7241?
Are you affected by CVE-2017-7241?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
