CVE
- Id
- 103617
- CVE No.
- CVE-2017-6797
- Status
- Candidate
- Description
- A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the "action_type" parameter.
- Phase
- Assigned (20170309)
- Votes
- None (candidate not yet proposed)
- Comments