Medium severity4.8NVD Advisory· Published Mar 31, 2017· Updated Jun 17, 2026
CVE-2017-7241
CVE-2017-7241
Description
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this vulnerability is not exploitable if the admin tools directory is removed, as recommended in the "Post-installation and upgrade tasks" of the MantisBT Admin Guide. A reminder to do so is also displayed on the login page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mantisbt/mantisbtPackagist | < 1.3.9 | 1.3.9 |
mantisbt/mantisbtPackagist | >= 2.0.0, < 2.1.3 | 2.1.3 |
mantisbt/mantisbtPackagist | >= 2.2.0, < 2.2.3 | 2.2.3 |
Affected products
36cpe:2.3:a:mantisbt:mantisbt:1.2.16:*:*:*:*:*:*:*+ 34 more
- cpe:2.3:a:mantisbt:mantisbt:1.2.16:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.2.17:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.2.18:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.2.19:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.2.20:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:1.3.9:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:mantisbt:mantisbt:2.3.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- www.mantisbt.org/bugs/view.phpnvdExploitPatchVendor AdvisoryWEB
- openwall.com/lists/oss-security/2017/03/30/4nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/97253nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-x53v-v9xp-gf6gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-7241ghsaADVISORY
- github.com/mantisbt/mantisbt/commit/2d55c6476e939db021128b3995c28dcae05b09a4ghsaWEB
- github.com/mantisbt/mantisbt/commit/d31841c806a3c8379fcf6c9d9559451270b0f1cbghsaWEB
- github.com/mantisbt/mantisbt/commit/ecef0e9b523a460709e8feedfce72f05bb30b992ghsaWEB
- www.securitytracker.com/id/1038169nvd
News mentions
0No linked articles in our index yet.