Cross-Site Scripting Vulnerability in Mantis Bug Tracker by MantisBT
CVE-2008-0404

Currently unrated

Key Information:

Vendor

Mantis

Status
Vendor
CVE Published:
23 January 2008

What is CVE-2008-0404?

A cross-site scripting (XSS) vulnerability exists in Mantis Bug Tracker prior to version 1.1.1, allowing remote attackers to inject arbitrary web scripts or HTML. This vulnerability is associated with vectors related to the 'Most active bugs' summary, which can be exploited to execute malicious scripts in the context of the user's session. Affected users may unknowingly perform actions or reveal sensitive information, posing a significant security risk to users and the integrity of the application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.