CVE-2014-8987
 
Severity Score
3.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via the config_option parameter, a different vulnerability than CVE-2014-8986.
Vulnerabilidad de XSS en la casilla 'set configuration' en la página Configuration Report (adm_config_report.php) en MantisBT 1.2.13 hasta la versión 1.2.17, permite a administradores remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro config_option, una vulnerabilidad diferente a CVE-2014-8986.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-11-19 CVE Reserved
- 2015-01-05 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2014/11/14/9 | Mailing List | |
http://www.openwall.com/lists/oss-security/2014/11/15/2 | Mailing List | |
http://www.openwall.com/lists/oss-security/2014/11/15/3 | Mailing List | |
http://www.openwall.com/lists/oss-security/2014/11/15/4 | Mailing List | |
http://www.openwall.com/lists/oss-security/2014/11/19/21 | Mailing List | |
https://github.com/mantisbt/mantisbt/commit/49c3d089 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.mantisbt.org/bugs/view.php?id=17870 | 2015-08-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mantisbt Search vendor "Mantisbt" | Mantisbt Search vendor "Mantisbt" for product "Mantisbt" | 1.2.13 Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.13" | - |
Affected
| ||||||
Mantisbt Search vendor "Mantisbt" | Mantisbt Search vendor "Mantisbt" for product "Mantisbt" | 1.2.14 Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.14" | - |
Affected
| ||||||
Mantisbt Search vendor "Mantisbt" | Mantisbt Search vendor "Mantisbt" for product "Mantisbt" | 1.2.15 Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.15" | - |
Affected
| ||||||
Mantisbt Search vendor "Mantisbt" | Mantisbt Search vendor "Mantisbt" for product "Mantisbt" | 1.2.16 Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.16" | - |
Affected
| ||||||
Mantisbt Search vendor "Mantisbt" | Mantisbt Search vendor "Mantisbt" for product "Mantisbt" | 1.2.17 Search vendor "Mantisbt" for product "Mantisbt" and version "1.2.17" | - |
Affected
|