View Issue Details

IDProjectCategoryView StatusLast Update
0012238mantisbtsecuritypublic2011-08-02 12:35
Reporterdhx Assigned Todhx  
PriorityimmediateSeveritymajorReproducibilityalways
Status closedResolutionfixed 
Product Version1.2.2 
Target Version1.2.3Fixed in Version1.2.3 
Summary0012238: XSS in print_all_bug_page_word.php when printing project and category names
Description

print_all_bug_page_word.php does not correctly sanitise project and category names. It is thus possible for a malicious user with project manager access permissions (or higher) to redirect users to print_all_bug_page_word.php to execute malicious JavaScript.

TagsNo tags attached.

Relationships

related to 0012371 closedgiallu XSS in print_all_bug_page_word.php when printing project and category names 

Activities

There are no notes attached to this issue.

Related Changesets

MantisBT: master bfc9e9ff

2010-08-05 04:00

dhx


Details Diff
Fix 0012238: XSS in print_all_bug_page_word.php project/category names

print_all_bug_page_word.php does not correctly sanitise project and
category names. It is thus possible for a malicious user with project
manager access permissions (or higher) to redirect users to
print_all_bug_page_word.php to execute malicious JavaScript.
Affected Issues
0012238
mod - print_all_bug_page_word.php Diff File

MantisBT: master-1.2.x 9fc1dd81

2010-08-05 04:00

dhx


Details Diff
Fix 0012238: XSS in print_all_bug_page_word.php project/category names

print_all_bug_page_word.php does not correctly sanitise project and
category names. It is thus possible for a malicious user with project
manager access permissions (or higher) to redirect users to
print_all_bug_page_word.php to execute malicious JavaScript.
Affected Issues
0012238
mod - print_all_bug_page_word.php Diff File