PT-2020-16231 · Mantisbt · Mantisbt
D3Vpoo1
·
Published
2020-09-30
·
Updated
2022-05-24
·
CVE-2020-25830
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MantisBT versions prior to 2.24.3
Description
An issue was discovered that allows an attacker to inject HTML and, if Content Security Policy (CSP) settings permit, achieve execution of arbitrary JavaScript when attempting to update a custom field via the
bug actiongroup page.php endpoint. The issue is due to improper escaping of a custom field's name.Recommendations
For versions prior to 2.24.3, update to version 2.24.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
bug actiongroup page.php endpoint to minimize the risk of exploitation. Additionally, review and adjust CSP settings to prevent the execution of arbitrary JavaScript.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mantisbt