CVE-2016-6837 | MantisBT up to 1.3.0/2.0.0-beta.1 Filter API view_all_bug_page.php view_type cross site scripting (Nessus ID 96992 / BID-92522)
A vulnerability was found in MantisBT up to 1.3.0/2.0.0-beta.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /mantis/view_all_bug_page.php of the component Filter API. The manipulation of the argument view_type with the input "><script>alert('XSS');</script> leads to cross site scripting.
This vulnerability is handled as CVE-2016-6837. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.