From 165feae3d8a8cbc2121660d32001bf6ac5b75359 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 9 Jun 2025 22:32:48 +0000 Subject: [PATCH] Publish GHSA-w93w-rx52-24qh --- .../GHSA-w93w-rx52-24qh.json | 37 +++++++++++++++---- 1 file changed, 29 insertions(+), 8 deletions(-) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-w93w-rx52-24qh/GHSA-w93w-rx52-24qh.json (65%) diff --git a/advisories/unreviewed/2022/05/GHSA-w93w-rx52-24qh/GHSA-w93w-rx52-24qh.json b/advisories/github-reviewed/2022/05/GHSA-w93w-rx52-24qh/GHSA-w93w-rx52-24qh.json similarity index 65% rename from advisories/unreviewed/2022/05/GHSA-w93w-rx52-24qh/GHSA-w93w-rx52-24qh.json rename to advisories/github-reviewed/2022/05/GHSA-w93w-rx52-24qh/GHSA-w93w-rx52-24qh.json index 9b1baf07ef1..d48c3d7c640 100644 --- a/advisories/unreviewed/2022/05/GHSA-w93w-rx52-24qh/GHSA-w93w-rx52-24qh.json +++ b/advisories/github-reviewed/2022/05/GHSA-w93w-rx52-24qh/GHSA-w93w-rx52-24qh.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-w93w-rx52-24qh", - "modified": "2022-05-17T02:13:50Z", + "modified": "2025-06-09T22:30:52Z", "published": "2022-05-17T02:13:50Z", "aliases": [ "CVE-2017-12062" ], + "summary": "MantisBT vulnerable to XSS via unsanitized filter field in manage_user_page.php", "details": "An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled.", "severity": [ { @@ -13,7 +14,27 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "mantisbt/mantisbt" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.5.2" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -23,6 +44,10 @@ "type": "WEB", "url": "https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7" }, + { + "type": "PACKAGE", + "url": "https://github.com/mantisbt/mantisbt" + }, { "type": "WEB", "url": "https://mantisbt.org/bugs/view.php?id=23166" @@ -34,10 +59,6 @@ { "type": "WEB", "url": "http://openwall.com/lists/oss-security/2017/08/01/2" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id/1039030" } ], "database_specific": { @@ -45,8 +66,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-06-09T22:30:51Z", "nvd_published_at": "2017-08-01T15:29:00Z" } } \ No newline at end of file