vulnerability

FreeBSD: VID-81FCC2F9-E15A-11E9-ABBF-800DD28B22BD (CVE-2019-15715): mantis -- multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Aug 28, 2019
Added
Sep 28, 2019
Modified
Jan 22, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-81FCC2F9-E15A-11E9-ABBF-800DD28B22BD:




The Mantis developers report:



CVE-2019-15715: [Admin Required - Post Authentication] Command Execution / Injection Vulnerability


CVE-2019-8331: In Bootstrap before 3.4.1, XSS is possible in the tooltip or popover data-template attribute


Missing integrity hashes for CSS resources from CDNs




Solution(s)

freebsd-upgrade-package-mantis-php71freebsd-upgrade-package-mantis-php72freebsd-upgrade-package-mantis-php73freebsd-upgrade-package-mantis-php74
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.