VYPR
Unrated severityNVD Advisory· Published May 15, 2014· Updated Jun 16, 2026

CVE-2013-1810

CVE-2013-1810

Description

Multiple cross-site scripting (XSS) vulnerabilities in core/summary_api.php in MantisBT 1.2.12 allow remote authenticated users with manager or administrator permissions to inject arbitrary web script or HTML via a (1) category name in the summary_print_by_category function or (2) project name in the summary_print_by_project function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Mantisbt/Mantisbt2 versions
    cpe:2.3:a:mantisbt:mantisbt:1.2.12:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mantisbt:mantisbt:1.2.12:*:*:*:*:*:*:*
    • (no CPE)range: 1.2.12

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.