Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-40598

3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters, on some specific server configurations this could poison the cache, leading to cross-site scripting. This issue has been fixed in version 2.28.2.

EPSS: Низкий
debian логотип

CVE-2026-40598

3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...

EPSS: Низкий
github логотип

GHSA-6jh4-47v2-4g37

3 месяца назад

MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-40598

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters, on some specific server configurations this could poison the cache, leading to cross-site scripting. This issue has been fixed in version 2.28.2.

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-40598

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...

0%
Низкий
3 месяца назад
github логотип
GHSA-6jh4-47v2-4g37

MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page

0%
Низкий
3 месяца назад

Уязвимостей на страницу