CVE

Id
103617  
CVE No.
CVE-2017-6797  
Status
Candidate  
Description
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the "action_type" parameter.  
Phase
Assigned (20170309)  
Votes
None (candidate not yet proposed)  
Comments