Количество 4
Количество 4
CVE-2020-25830
An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php.
CVE-2020-25830
An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php.
CVE-2020-25830
An issue was discovered in MantisBT before 2.24.3. Improper escaping o ...
GHSA-2pm7-q8pc-xhvq
MantisBT HTML Injection vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-25830 An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php. | CVSS3: 4.8 | 1% Низкий | больше 5 лет назад | |
CVE-2020-25830 An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php. | CVSS3: 4.8 | 1% Низкий | больше 5 лет назад | |
CVE-2020-25830 An issue was discovered in MantisBT before 2.24.3. Improper escaping o ... | CVSS3: 4.8 | 1% Низкий | больше 5 лет назад | |
GHSA-2pm7-q8pc-xhvq MantisBT HTML Injection vulnerability | CVSS3: 4.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу