Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in core/summary_api.php in MantisBT 1.2.12 allow remote authenticated users with manager or administrator permissions to inject arbitrary web script or HTML via a (1) category name in the summary_print_by_category function or (2) project name in the summary_print_by_project function.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mantisbt | Mantisbt | 1.2.12 |
Related Weaknesses (CWE)
References
- http://seclists.org/oss-sec/2013/q1/127
- http://seclists.org/oss-sec/2013/q1/556
- http://secunia.com/advisories/51853Vendor Advisory
- http://www.mantisbt.org/bugs/view.php?id=15384
- http://seclists.org/oss-sec/2013/q1/127
- http://seclists.org/oss-sec/2013/q1/556
- http://secunia.com/advisories/51853Vendor Advisory
- http://www.mantisbt.org/bugs/view.php?id=15384
FAQ
What is CVE-2013-1810?
CVE-2013-1810 is a vulnerability with a CVSS score of 2.1 (LOW). Multiple cross-site scripting (XSS) vulnerabilities in core/summary_api.php in MantisBT 1.2.12 allow remote authenticated users with manager or administrator permissions to inject arbitrary web script...
How severe is CVE-2013-1810?
CVE-2013-1810 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1810?
Check the references section above for vendor advisories and patch information. Affected products include: Mantisbt Mantisbt.