Описание
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (my_view_page.php) allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript, when displaying a tag that has been renamed or deleted. Version 2.28.1 contains a patch. Workarounds include editing offending History entries (using SQL) and wrapping $this->tag_name in a string_html_specialchars() call in IssueTagTimelineEvent::html().
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:mantisbt:mantisbt:2.28.0:*:*:*:*:*:*:*
EPSS
Процентиль: 9%
0.00196
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
debian
5 месяцев назад
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...
CVSS3: 6.1
github
5 месяцев назад
MantisBT has Stored HTML Injection/XSS when displaying Tags in Timeline
EPSS
Процентиль: 9%
0.00196
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79