PT-2026-27182 · Unknown · Mantis Bug Tracker

Shukla304

·

Publicado

2026-03-23

·

Atualizado

2026-03-25

·

CVE-2026-33517

CVSS v4.0

8.6

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mantis Bug Tracker versions prior to 2.28.1
Description Mantis Bug Tracker is an open source issue tracker. A flaw exists in version 2.28.0 where improper escaping of a tag name during the display of a confirmation message when deleting a tag (via the tag delete.php script) allows an attacker to inject HTML. If Content Security Policy (CSP) settings permit, this can lead to the execution of arbitrary JavaScript. The vulnerable parameter is the tag name displayed in the confirmation message.
Recommendations Upgrade to Mantis Bug Tracker version 2.28.1 or later. As a temporary workaround, revert commit d6890320752ecf37bd74d11fe14fe7dc12335be9. As a temporary workaround, manually edit language files to remove the sprintf placeholder %1$s from the $s tag delete message string.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33517
GHSA-FH48-F69W-7VMP

Produtos afetados

Mantis Bug Tracker