CVE-2017-6797: Mantisbt
Medium severity, CVSS 6.1. EPSS: 2.3% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter.
Affected products
- Mantisbt Mantisbt: before 1.3.7 (fixed in 1.3.7); from 2.0.0, before 2.2.1 (fixed in 2.2.1)
Published 2017-03-10. Last modified 2026-06-17.