CVE-2014-8987

Publication date 24 August 2015

Last updated 24 July 2024


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via the config_option parameter, a different vulnerability than CVE-2014-8986.

Read the notes from the security team

Status

Package Ubuntu Release Status
mantis 14.10 utopic Not in release
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid
Not affected

Notes


jdstrand

per Debian, affected code introduced later


Access our resources on patching vulnerabilities