Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 539528 (CVE-2015-2046) - www-apps/mantisbt: XSS in adm_config_report.php (CVE-2015-2046)
Summary: www-apps/mantisbt: XSS in adm_config_report.php (CVE-2015-2046)
Status: RESOLVED FIXED
Alias: CVE-2015-2046
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://seclists.org/oss-sec/2015/q1/484
Whiteboard: B4 [upstream/ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-02-09 21:41 UTC by Kristian Fiskerstrand (RETIRED)
Modified: 2016-04-01 03:46 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-02-09 21:41:02 UTC
From ${URL}:
Greetings,

Please assign a CVE ID for the following issue

Description:

The MantisBT Configuration Report (adm_config_report.php) did not properly sanitize the form variables used when saving a filter, allowing an attacker to embed JavaScript code which would be executed in the client's browser when displaying the page.

Affected versions:
- >= 1.2.13
- 1.3.0-beta.1

Fixed in versions:
- 1.2.20 (not yet released)
- 1.3.0-beta.2 (not yet released)

Patch:
See Github [1]

Credit:
This vulnerability was discovered by Fortinet's FortiGuard Labs (reference FG-VD-15-008 [2])
The issue was fixed by Damien Regad (MantisBT Developer).

References:
Further details will be available in our issue tracker [2] once this goes public.

[1] https://github.com/mantisbt/mantisbt/commit/6defeed5 (1.2.x)
    https://github.com/mantisbt/mantisbt/commit/3c6f6e56 (1.3.x)
[2] http://www.fortiguard.com/advisory/UpcomingAdvisories.html
[3] https://www.mantisbt.org/bugs/view.php?id=19301
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-03-07 08:27:46 UTC
Multiple vulnerabilities spread across 9 different bugs.  No movement from maintainers in over a year.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-04-01 03:46:36 UTC
Package removed