CVE-2017-6797: Mantisbt

Medium severity, CVSS 6.1. EPSS: 2.3% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter.

Affected products

  • Mantisbt Mantisbt: before 1.3.7 (fixed in 1.3.7); from 2.0.0, before 2.2.1 (fixed in 2.2.1)

Published 2017-03-10. Last modified 2026-06-17.