Description
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-32950 | MantisBT vulnerable to XSS via unescaped output in browser_search_plugin.php |
Github GHSA |
GHSA-wfg2-2wmw-6894 | MantisBT vulnerable to XSS via unescaped output in browser_search_plugin.php |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T05:56:15.606Z
Reserved: 2022-04-04T00:00:00.000Z
Link: CVE-2022-28508
No data.
Status : Modified
Published: 2022-05-04T14:15:09.050
Modified: 2024-11-21T06:57:27.417
Link: CVE-2022-28508
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA