View Issue Details

IDProjectCategoryView StatusLast Update
0012371mantisbtsecuritypublic2014-09-23 18:05
Reportergiallu Assigned Togiallu  
PriorityimmediateSeveritymajorReproducibilityalways
Status closedResolutionfixed 
Product Version1.1.8 
Fixed in Version1.2.9 
Summary0012371: XSS in print_all_bug_page_word.php when printing project and category names
Description

print_all_bug_page_word.php does not correctly sanitise project and category names. It is thus possible for a malicious user with project manager access permissions (or higher) to redirect users to print_all_bug_page_word.php to execute malicious JavaScript.

TagsNo tags attached.

Relationships

related to 0012238 closeddhx XSS in print_all_bug_page_word.php when printing project and category names 
related to 0015721 closedgrangeway Functionality to consider porting to master-2.0.x 

Activities

grangeway

grangeway

2013-04-05 17:57

reporter   ~0036238

Marking as 'acknowledged' not resolved/closed to track that change gets ported to master-2.0.x branch

Related Changesets

MantisBT: master-1.1.x 3bc117fc

2010-09-18 19:29

giallu


Details Diff
Fix 0012371: XSS in print_all_bug_page_word.php project/category names

Backport of commit bfc9e9 for bug 12238
Affected Issues
0012371
mod - print_all_bug_page_word.php Diff File