MantisBT allows XSS in manage_custom_field_edit_page.php
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 29, 2025
Description
Published by the National Vulnerability Database
Jun 17, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
May 29, 2025
Reviewed
May 29, 2025
An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
References