MantisBT vulnerable to XSS due to improper escape in manage_plugin_page.php and manage_plugin_uninstall.php
Moderate severity
GitHub Reviewed
Published
Apr 14, 2022
to the GitHub Advisory Database
•
Updated Jun 9, 2025
Description
Published by the National Vulnerability Database
Apr 13, 2022
Published to the GitHub Advisory Database
Apr 14, 2022
Reviewed
Jun 9, 2025
Last updated
Jun 9, 2025
An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.
References