CVE-2017-6958
Summary
| CVE | CVE-2017-6958 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-17 09:59:00 UTC |
| Updated | 2021-04-12 13:02:00 UTC |
| Description | An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by crafting any valid parameter. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mantisbt | Mantisbt Source Integration Plugin | All | All | All | All |
| Application | Mantisbt | Source Integration | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-6958: XSS in search page · Issue #205 · mantisbt-plugins/source-integration · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.