CVE-2017-12062
Estado: ModificadaMedia (6.1)—
An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.90%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- http://openwall.com/lists/oss-security/2017/08/01/1
- http://openwall.com/lists/oss-security/2017/08/01/2
- http://www.securitytracker.com/id/1039030
- https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7
- https://mantisbt.org/bugs/view.php?id=23166
- http://openwall.com/lists/oss-security/2017/08/01/1
- http://openwall.com/lists/oss-security/2017/08/01/2
- http://www.securitytracker.com/id/1039030
- https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7
- https://mantisbt.org/bugs/view.php?id=23166
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-12062",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-08-01T15:29:00.593",
"references": [
{
"url": "http://openwall.com/lists/oss-security/2017/08/01/1",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://openwall.com/lists/oss-security/2017/08/01/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id/1039030",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://mantisbt.org/bugs/view.php?id=23166",
"tags": [
"Exploit",
"Issue Tracking",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://openwall.com/lists/oss-security/2017/08/01/1",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://openwall.com/lists/oss-security/2017/08/01/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1039030",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/mantisbt/mantisbt/commit/9b5b71dadbeeeec27efea59f562ac5bd6d2673b7",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://mantisbt.org/bugs/view.php?id=23166",
"tags": [
"Exploit",
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled."
},
{
"lang": "es",
"value": "Se detectó una vulnerabilidad de tipo Cross-Site Scripting (XSS) en manage_user_page.php en MantisBT en sus versiones 2.X anteriores a la 2.5.2. El campo \"filter\" no se sanitiza antes de que se renderice en la página Manage User, permitiendo a los atacantes remotos ejecutar código JavaScript arbitrario si se deshabilita la política de seguridad de contenido (CSP)."
}
],
"lastModified": "2026-06-17T01:02:37.100",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E6AF670-28C3-4D7E-9EB4-E0B366CE818E"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "021CC8F4-B310-4DBF-9D50-B8A357158E4D"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D73E7205-12E1-4C57-A120-91C4C0760305"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "262EC0CC-0716-4AED-9255-13288A297879"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2550F1FD-5104-4BAA-80F6-C6202D7326B4"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AAFDE5FC-B891-4ACA-BCAB-83EB9D49C91F"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F89D994-7F93-4839-8A57-F4CD633576E8"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2154CE53-2DED-4023-96D5-515468E226B0"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFF4779C-8E14-4CB1-BCB4-80F4C5020629"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83C79C70-F6BE-485D-952A-44E5E9F16D39"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B5AE145-E1B4-40EF-A3B8-A13C114D3D3B"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A77FD43E-A573-408F-A566-0959DAF442AD"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.3.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CCB5C9D9-8EC1-46C7-BB09-84ED20E6E61E"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9258FCA1-6948-4DFE-BE50-5A39B5A64120"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4582B6DC-A625-41B2-ABF8-CF3BCF90A590"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F06B9BB-77DF-4185-A496-88DA8DABDDB4"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE637AB4-0E47-4063-8CFF-F163A27D7F14"
},
{
"criteria": "cpe:2.3:a:mantisbt:mantisbt:2.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75EE73EE-2A07-48BE-B7B9-C21643EC25B8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}