CVE
- Id
- 103793
- CVE No.
- CVE-2017-6973
- Status
- Candidate
- Description
- A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted "action" parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.
- Phase
- Assigned (20170317)
- Votes
- None (candidate not yet proposed)
- Comments