CVE-2014-9701
Summary
| CVE | CVE-2014-9701 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-09 18:29:00 UTC |
| Updated | 2017-08-17 17:49:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter to permalink_page.php. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1202885 – (CVE-2014-9701) CVE-2014-9701 mantis: XSS issue in MantisBT permalink_page.php | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory, VDB Entry |
| oss-security - Re: CVE Request: XSS issue in MantisBT permalink_page.php | MLIST | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| Fix URL redirection issue in login_page.php · mantisbt/mantisbt@e7e2b55 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Fix URL redirection issue in login_page.php · mantisbt/mantisbt@d95f070 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| 0019493: CVE-2014-9701: XSS vulnerability in permalink_page.php - MantisBT | CONFIRM | www.mantisbt.org | Vendor Advisory |
| 0017362: Multiple vulnerabilities in MantisBT - MantisBT | CONFIRM | www.mantisbt.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.