Medium severity4.7NVD Advisory· Published Feb 17, 2017· Updated Jun 17, 2026
CVE-2016-7111
CVE-2016-7111
Description
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mantisbt/mantisbtPackagist | < 1.3.1 | 1.3.1 |
mantisbt/mantisbtPackagist | >= 2.0.0-beta.1, < 2.0.0-beta.2 | 2.0.0-beta.2 |
Affected products
3Patches
Vulnerability mechanics
References
7- www.openwall.com/lists/oss-security/2016/08/29/2nvdMailing ListPatchThird Party AdvisoryWEB
- github.com/mantisbt/mantisbt/commit/b3511d2fnvdPatch
- mantisbt.org/bugs/view.phpnvdPatchVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2016/08/28/1nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-8vx9-hcvq-gfv8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-7111ghsaADVISORY
- github.com/mantisbt/mantisbt/commit/b3511d2feb47eaee41feb5f69cf3c8a2c9acd229ghsaWEB
News mentions
0No linked articles in our index yet.