Description
An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-30711 | MantisBT vulnerable to XSS due to improper escape in manage_plugin_page.php and manage_plugin_uninstall.php |
Github GHSA |
GHSA-rqgj-rqfr-5j6f | MantisBT vulnerable to XSS due to improper escape in manage_plugin_page.php and manage_plugin_uninstall.php |
References
| Link | Providers |
|---|---|
| https://mantisbt.org/bugs/view.php?id=29688 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T04:56:37.928Z
Reserved: 2022-02-26T00:00:00.000Z
Link: CVE-2022-26144
No data.
Status : Modified
Published: 2022-04-13T14:15:09.273
Modified: 2024-11-21T06:53:31.147
Link: CVE-2022-26144
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA