Cross-Site Scripting Vulnerability in Mantis Bug Tracker
CVE-2008-3331

Currently unrated

Key Information:

Vendor

Mantis

Status
Vendor
CVE Published:
27 July 2008

Badges

👾 Exploit Exists

What is CVE-2008-3331?

A cross-site scripting vulnerability exists in the return_dynamic_filters.php file of Mantis Bug Tracker prior to version 1.1.2. This flaw allows remote attackers to exploit the filter_target parameter, injecting arbitrary web scripts or HTML into pages viewed by users. Successful exploitation of this vulnerability could lead to the execution of malicious scripts in the context of the affected user’s browser, potentially compromising the integrity of user data and session management.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.