CVE-2023-49802
CVSS V2 None
CVSS V3 None
Description
The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1, cross-site scripting in the MantisBT LinkedCustomFields plugin allows Javascript execution, when a crafted Custom Field is linked via the plugin and displayed when reporting a new Issue or editing an existing one. This issue is fixed in version 2.0.1. As a workaround, one may utilize MantisBT's default Content Security Policy, which blocks script execution.
Overview
- CVE ID
- CVE-2023-49802
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-12-11T21:11:53.407Z
- Last Modified Date
- 2023-12-11T21:11:53.407Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/mantisbt-plugins/LinkedCustomFields/security/advisories/GHSA-2f37-9xpx-5hhw | x_refsource_CONFIRM |
https://github.com/mantisbt-plugins/LinkedCustomFields/issues/10 | x_refsource_MISC |
https://github.com/mantisbt-plugins/LinkedCustomFields/pull/11 | x_refsource_MISC |
https://github.com/mantisbt-plugins/LinkedCustomFields/commit/30e5ae751e40d7ae18bfd794fd48671477b3d286 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-49802 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49802 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 12:40:44 | Added to TrackCVE |