Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-7222
Description:A cross-site scripting (XSS) vulnerability in MantisBT before 2.1.1 allows remote attackers to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by modifying 'window_title' in the application configuration. This requires privileged access to MantisBT configuration management pages (i.e., administrator access rights) or altering the system configuration file (config_inc.php).
Test IDs: 1.3.6.1.4.1.25623.1.0.108104   1.3.6.1.4.1.25623.1.0.108103  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-7222




© 1998-2025 E-Soft Inc. All rights reserved.