Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.3 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) a plugin name, related to manage_plugin_uninstall.php; (2) an enumeration value or (3) a String value of a custom field, related to core/cfdefs/cfdef_standard.php; or a (4) project or (5) category name to print_all_bug_page_word.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mantisbt Mantis多个跨站脚本攻击漏洞
Vulnerability Description
MantisBT是MantisBT团队的一套基于Web的开源缺陷跟踪系统。该系统以Web操作的形式提供项目管理及缺陷跟踪服务。 MantisBT 1.2.3之前版本中存在多个跨站脚本攻击漏洞。远程认证管理员可以借助(1)与manage_plugin_uninstall.php文件有关的插件名;(2)枚举值或者(3)与core/cfdefs/cfdef_standard.php文件有关的自定义域的字符串值;或者(4)与print_all_bug_page_word.php有关的工程或(5)类别名注入任意we
CVSS Information
N/A
Vulnerability Type
N/A