Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Regad

#40474of 53,622
6.7Total CVSS
Vulnerabilities · 1
PT-2023-31360
6.7
2023-12-11
Mantisbt · Mantisbt Linkedcustomfields Plugin · CVE-2023-49802
**Name of the Vulnerable Software and Affected Versions** MantisBT LinkedCustomFields plugin versions prior to 2.0.1 **Description** The issue allows cross-site scripting in the MantisBT LinkedCustomFields plugin, enabling Javascript execution when a crafted Custom Field is linked via the plugin and displayed when reporting a new Issue or editing an existing one. This can be mitigated by utilizing MantisBT's default Content Security Policy, which blocks script execution. **Recommendations** For versions prior to 2.0.1, update to version 2.0.1 to resolve the issue. As a temporary workaround, consider utilizing MantisBT's default Content Security Policy to block script execution.