MantisBT: master-2.17 66091a42

Author Committer Branch Timestamp Parent
dregad dregad master-2.17 2018-09-04 15:39 master c6b2dd5b
Affected Issues  0024731: CVE-2018-16514: Reflected XSS in view_filters_page.php via core/filter_form_api.php
Changeset

Use SCRIPT_NAME instead of PHP_SELF

Fix XSS in view_filters_page.php and manage_filter_edit_page.php

Fixes 0024731

mod - core/filter_form_api.php Diff File