Количество 3
Количество 3
CVE-2026-34463
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue originating from a Project other than the current one, the clone form (bug_report_page.php) prepends the source Project name before the category selector without proper escaping, allowing an attacker able to to inject HTML if they can set the Project's name (which typically requires manager or administrator access level). This issue has been resolved in version 2.28.2.
CVE-2026-34463
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Version ...
GHSA-fvjf-68wh-rwp2
MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-34463 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue originating from a Project other than the current one, the clone form (bug_report_page.php) prepends the source Project name before the category selector without proper escaping, allowing an attacker able to to inject HTML if they can set the Project's name (which typically requires manager or administrator access level). This issue has been resolved in version 2.28.2. | 0% Низкий | 3 месяца назад | ||
CVE-2026-34463 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Version ... | 0% Низкий | 3 месяца назад | ||
GHSA-fvjf-68wh-rwp2 MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу