Описание
MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when resolving or closing issues (bug_change_status_page.php) belonging to a project linking said custom field, viewing issues (view_all_bug_page.php) when the custom field is displayed as a column, or printing issues (print_all_bug_page.php) when the custom field is displayed as a column. Version 2.26.2 contains a patch for the issue. As a workaround, ensure Custom Field Names do not contain HTML tags.
Ссылки
- Patch
- PatchVendor Advisory
- Issue TrackingMitigationVendor Advisory
- Patch
- PatchVendor Advisory
- Issue TrackingMitigationVendor Advisory
Уязвимые конфигурации
EPSS
6.6 Medium
CVSS3
4.8 Medium
CVSS3
Дефекты
Связанные уязвимости
MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improp ...
Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting
EPSS
6.6 Medium
CVSS3
4.8 Medium
CVSS3