Skip to content

Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting

Moderate severity GitHub Reviewed Published May 12, 2024 in mantisbt/mantisbt • Updated May 24, 2024

Package

composer mantisbt/mantisbt (Composer)

Affected versions

< 2.26.2

Patched versions

2.26.2

Description

Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when:

  • resolving or closing issues (bug_change_status_page.php) belonging to a project linking said custom field
  • viewing issues (view_all_bug_page.php) when the custom field is displayed as a column
  • printing issues (print_all_bug_page.php) when the custom field is displayed as a column

Impact

Cross-site scripting (XSS).

Patches

mantisbt/mantisbt@447a521

Workarounds

Ensure Custom Field Names do not contain HTML tags.

References

References

@dregad dregad published to mantisbt/mantisbt May 12, 2024
Published to the GitHub Advisory Database May 13, 2024
Reviewed May 13, 2024
Published by the National Vulnerability Database May 14, 2024
Last updated May 24, 2024

Severity

Moderate
6.6
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Weaknesses

CVE ID

CVE-2024-34081

GHSA ID

GHSA-wgx7-jp56-65mq

Source code

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.