Количество 3
Количество 3
CVE-2022-33910
An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or an admin clicks on the attachment, file_download.php opens the SVG document in a browser tab instead of downloading it as a file, causing the JavaScript code to execute.
CVE-2022-33910
An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers ...
GHSA-qghg-v7xv-q98q
MantisBT XSS through crafted SVG documents in file_download.php
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-33910 An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or an admin clicks on the attachment, file_download.php opens the SVG document in a browser tab instead of downloading it as a file, causing the JavaScript code to execute. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
CVE-2022-33910 An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers ... | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-qghg-v7xv-q98q MantisBT XSS through crafted SVG documents in file_download.php | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу