Medium severity5.4NVD Advisory· Published Oct 31, 2019· Updated Jun 16, 2026
CVE-2013-1934
CVE-2013-1934
Description
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7<1.2.14+ 5 more
- (no CPE)range: <1.2.14
- (no CPE)range: 1.2.0rc1 before 1.2.14
- cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*range: >=1.2.1,<=1.2.14
- cpe:2.3:a:mantisbt:mantisbt:1.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.2.0:rc2:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- www.debian.org/security/2015/dsa-3120nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2013/04/09/1nvdMailing ListThird Party Advisory
- mantisbt.org/bugs/view.phpnvdIssue TrackingVendor Advisory
- security-tracker.debian.org/tracker/CVE-2013-1934nvdThird Party Advisory
News mentions
0No linked articles in our index yet.