Cross-Site Scripting Vulnerability in Mantis Bug Tracker by MantisBT
CVE-2008-0404
Currently unrated
What is CVE-2008-0404?
A cross-site scripting (XSS) vulnerability exists in Mantis Bug Tracker prior to version 1.1.1, allowing remote attackers to inject arbitrary web scripts or HTML. This vulnerability is associated with vectors related to the 'Most active bugs' summary, which can be exploited to execute malicious scripts in the context of the user's session. Affected users may unknowingly perform actions or reveal sensitive information, posing a significant security risk to users and the integrity of the application.
