Learn about CVE-2017-6797, a cross-site scripting (XSS) vulnerability in MantisBT versions prior to 1.3.7 and 2.x prior to 2.2.1, allowing remote attackers to inject malicious JavaScript code.
A cross-site scripting (XSS) vulnerability in MantisBT versions prior to 1.3.7 and 2.x prior to 2.2.1 allows remote attackers to inject arbitrary JavaScript code via the 'action_type' parameter.
Understanding CVE-2017-6797
An issue of cross-site scripting (XSS) vulnerability has been identified in the bug_change_status_page.php file of MantisBT versions prior to 1.3.7 and 2.x prior to 2.2.1.
What is CVE-2017-6797?
This vulnerability enables attackers from remote locations to inject any JavaScript code of their choice using the 'action_type' parameter.
The Impact of CVE-2017-6797
Technical Details of CVE-2017-6797
A cross-site scripting (XSS) vulnerability in MantisBT versions prior to 1.3.7 and 2.x prior to 2.2.1.
Vulnerability Description
The bug_change_status_page.php file allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter.
Affected Systems and Versions
Exploitation Mechanism
Attackers exploit the vulnerability by injecting malicious JavaScript code through the 'action_type' parameter.
Mitigation and Prevention
Immediate Steps to Take: