Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rrc-5vp6-m3f6

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

MantisBT XSS issue on the view_all_bug_page.php

An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CSP settings allow it).

Пакеты

Наименование

mantisbt/mantisbt

composer
Затронутые версииВерсия исправления

>= 2.1.0, <= 2.24.1

2.24.2

EPSS

Процентиль: 50%
0.00274
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CSP settings allow it).

CVSS3: 5.4
debian
больше 5 лет назад

An XSS issue was discovered in MantisBT before 2.24.2. Improper escapi ...

EPSS

Процентиль: 50%
0.00274
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79