Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. mantisbt/mantisbt
  4. ›
  5. CVE-2017-7241

CVE-2017-7241: MantisBT XSS via move_attachments_page.php

May 17, 2022 (updated June 11, 2025)

A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted ’type’ parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this vulnerability is not exploitable if the admin tools directory is removed, as recommended in the “Post-installation and upgrade tasks” of the MantisBT Admin Guide. A reminder to do so is also displayed on the login page.

References

  • github.com/advisories/GHSA-x53v-v9xp-gf6g
  • github.com/mantisbt/mantisbt
  • github.com/mantisbt/mantisbt/commit/2d55c6476e939db021128b3995c28dcae05b09a4
  • github.com/mantisbt/mantisbt/commit/d31841c806a3c8379fcf6c9d9559451270b0f1cb
  • github.com/mantisbt/mantisbt/commit/ecef0e9b523a460709e8feedfce72f05bb30b992
  • nvd.nist.gov/vuln/detail/CVE-2017-7241

Code Behaviors & Features

Detect and mitigate CVE-2017-7241 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.3.9, all versions starting from 2.0.0 before 2.1.3, all versions starting from 2.2.0 before 2.2.3

Fixed versions

  • 1.3.9
  • 2.1.3
  • 2.2.3

Solution

Upgrade to versions 1.3.9, 2.1.3, 2.2.3 or above.

Impact 4.8 MEDIUM

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

packagist/mantisbt/mantisbt/CVE-2017-7241.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 10 Feb 2026 00:20:18 +0000.