View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0012230 | mantisbt | security | public | 2010-08-04 09:13 | 2015-03-15 20:07 |
Reporter | jreese | Assigned To | |||
Priority | normal | Severity | minor | Reproducibility | always |
Status | closed | Resolution | fixed | ||
Product Version | 1.2.2 | ||||
Target Version | 1.2.3 | Fixed in Version | 1.2.3 | ||
Summary | 0012230: CVE-2010-2574: XSS vulnerability when deleting maliciously named categories | ||||
Description | As reported by Secunia, SA40832, there is an XSS vulnerability when deleting categories that have been maliciously named. Chance of attack is extremely low due to requiring project manager access. | ||||
Additional Information | Official Secunia announcement: http://secunia.com/advisories/40832/ | ||||
Tags | No tags attached. | ||||
All fixed, thanks John :) |
|
Official Secunia announcement: http://secunia.com/advisories/40832/ |
|
For future reference, this is also CVE-2010-2574 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2574) |
|
MantisBT: master 083c34f0 2010-08-04 09:17 Details Diff |
Fix 0012230: XSS vulnerability when deleting maliciously named categories As reported by Secunia, SA40832, there is an XSS vulnerability when deleting project categories that have been maliciously named. The chance of attack is low due to requiring project manager access to create malicious project categories in the first place. Thanks to John Reese for debugging this issue. |
Affected Issues 0012230 |
|
mod - manage_proj_cat_delete.php | Diff File | ||
MantisBT: master-1.2.x a374a7c9 2010-08-04 09:17 Details Diff |
Fix 0012230: XSS vulnerability when deleting maliciously named categories As reported by Secunia, SA40832, there is an XSS vulnerability when deleting project categories that have been maliciously named. The chance of attack is low due to requiring project manager access to create malicious project categories in the first place. Thanks to John Reese for debugging this issue. |
Affected Issues 0012230 |
|
mod - manage_proj_cat_delete.php | Diff File |