View Issue Details

IDProjectCategoryView StatusLast Update
0020108mantisbtsecuritypublic2016-04-04 11:07
Reporterdregad Assigned Todregad  
PriorityhighSeveritymajorReproducibilityalways
Status closedResolutionduplicate 
Platformubuntu 14.01 
Product Version1.3.0-beta.1 
Target Version1.3.0-beta.3Fixed in Version1.3.0-beta.3 
Summary0020108: CVE-2015-2046 : XSS in adm_config_report.php (FG-VD-15-008)
Description

This is a clone of 0019301 to track the vulnerability in 1.3.x branch

TagsNo tags attached.

Relationships

duplicate of 0019301 closeddregad CVE-2015-2046 : XSS in adm_config_report.php (FG-VD-15-008) 

Activities

There are no notes attached to this issue.

Related Changesets

MantisBT: master 3c6f6e56

2015-01-30 12:50

dregad


Details Diff
Fix 0019301: XSS in adm_config_report.php

The 'filter_config_id' was not properly sanitized before being
displayed.

This vulnerability was discovered by Fortinet's FortiGuard Labs.
Affected Issues
0019301, 0020108
mod - adm_config_report.php Diff File