PT-2020-14855 · Mantisbt · Mantisbt

Jaime Andrés Restrepo

·

Published

2020-08-12

·

Updated

2022-05-24

·

CVE-2020-16266

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MantisBT versions prior to 2.24.2
Description A security issue was found that allows a remote attacker to inject arbitrary HTML into a page by saving it into a text Custom Field. This occurs due to improper escaping on the view all bug page.php page, potentially leading to code execution in the browser of any user viewing the issue, provided the Content Security Policy (CSP) settings permit it.
Recommendations For versions prior to 2.24.2, update to version 2.24.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the view all bug page.php page or custom fields to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-16266
GHSA-4RRC-5VP6-M3F6

Affected Products

Mantisbt