GHSA-8vx9-hcvq-gfv8
Dashboard / Vulnerabilities / GHSA-8vx9-hcvq-gfv8
Summary: MantisBT XSS through weak CSP when using Gravatar plugin
Details: MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-7111, https://github.com/mantisbt/mantisbt/commit/b3511d2feb47eaee41feb5f69cf3c8a2c9acd229, https://github.com/mantisbt/mantisbt, https://mantisbt.org/bugs/view.php?id=21263, http://www.openwall.com/lists/oss-security/2016/08/28/1, http://www.openwall.com/lists/oss-security/2016/08/29/2
Affected packages
Package
Name: mantisbt/mantisbt
Purl: pkg:composer/mantisbt/mantisbt
Affected ranges
Type: ECOSYSTEM
Events:
