Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-40597

3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the Content Security Policy's script-src directive by uploading a crafted attachment to any issue that, when accessed via the file_download.php link, will be downloaded with a valid JavaScript MIME type resulting in script execution. The uploaded payload must be sniffed as a valid JavaScript MIME type by PHP finfo (see file_create_finfo() API function). Non-JavaScript MIME types will not get imported in a <script> tag by the browser, due to response header X-Content-Type-Options being set to nosniff, which requires all imported JavaScript files to be a valid JavaScript MIME type. This issue has been fixed in version 2.28.2.

EPSS: Низкий
debian логотип

CVE-2026-40597

3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...

EPSS: Низкий
github логотип

GHSA-9c3j-xm6v-j7j3

3 месяца назад

MantisBT has a Content Security Policy bypass via attachments

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-40597

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the Content Security Policy's script-src directive by uploading a crafted attachment to any issue that, when accessed via the file_download.php link, will be downloaded with a valid JavaScript MIME type resulting in script execution. The uploaded payload must be sniffed as a valid JavaScript MIME type by PHP finfo (see file_create_finfo() API function). Non-JavaScript MIME types will not get imported in a <script> tag by the browser, due to response header X-Content-Type-Options being set to nosniff, which requires all imported JavaScript files to be a valid JavaScript MIME type. This issue has been fixed in version 2.28.2.

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-40597

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...

0%
Низкий
3 месяца назад
github логотип
GHSA-9c3j-xm6v-j7j3

MantisBT has a Content Security Policy bypass via attachments

0%
Низкий
3 месяца назад

Уязвимостей на страницу