{"id":"GHSA-3qv7-98vm-xx2v","summary":"MantisBT cross-site scripting (XSS) vulnerability through crafted PATH_INFO","details":"A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-13055.","aliases":["CVE-2018-16514"],"modified":"2025-05-29T16:14:30.754250Z","published":"2022-05-24T16:48:31Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-05-29T15:23:15Z","nvd_published_at":"2019-06-20T14:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16514"},{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/commit/66091a42626631a3063774eb0fb8a4218ab22fd4"},{"type":"PACKAGE","url":"https://github.com/mantisbt/mantisbt"},{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/blob/006cd0cd90c37097e1a065fd3e59ce2534490834/core/filter_form_api.php#L2779"},{"type":"WEB","url":"https://mantisbt.org/bugs/view.php?id=24731"}],"affected":[{"package":{"name":"mantisbt/mantisbt","ecosystem":"Packagist","purl":"pkg:composer/mantisbt/mantisbt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.17.1"}]}],"versions":["2.10.0","2.10.1","2.11.0","2.11.1","2.12.0","2.12.1","2.12.2","2.13.0","2.13.1","2.13.2","2.14.0","2.15.0","2.15.1","2.16.0","2.16.1","2.17.0","2.3.0","2.3.1","2.3.2","2.3.3","2.4.0","2.4.1","2.4.2","2.5.0","2.5.1","2.5.2","2.6.0","2.7.0","2.7.1","2.8.0","2.8.1","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3qv7-98vm-xx2v/GHSA-3qv7-98vm-xx2v.json","last_known_affected_version_range":"\u003c= 2.17.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}