Medium severity6.1NVD Advisory· Published Aug 3, 2018· Updated Jun 17, 2026
CVE-2018-14504
CVE-2018-14504
Description
An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with a crafted name (e.g., 'foobar" onclick="alert(1)').
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mantisbt/mantisbtPackagist | >= 2.0.0, < 2.15.1 | 2.15.1 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/mantisbt/mantisbt/commit/8b5fa243dbf04344a55fe880135ec149fc1f439fnvdPatchThird Party AdvisoryWEB
- mantisbt.org/bugs/view.phpnvdExploitIssue TrackingPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-74gh-5j33-vg4wghsaADVISORY
- mantisbt.org/blog/archives/mantisbt/602nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-14504ghsaADVISORY
News mentions
0No linked articles in our index yet.