Cross-Site Scripting Vulnerabilities in Mantis by Mantishub
CVE-2006-0841

Currently unrated

Key Information:

Vendor

Mantis

Status
Vendor
CVE Published:
22 February 2006

What is CVE-2006-0841?

Multiple cross-site scripting vulnerabilities in Mantis 1.00rc4 and earlier enable remote attackers to inject arbitrary web scripts or HTML through various parameters in key PHP files. These exploitable parameters include hide_status, handler_id, and user_monitor, amongst others, found in view_all_set.php, manage_user_page.php, view_filters_page.php, and proj_doc_delete.php. Successful exploitation can lead to unauthorized access or manipulation of user sessions.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.