Cross-Site Scripting Vulnerability in MantisBT by MantisBT
CVE-2021-33557

6.1MEDIUM

Key Information:

Vendor

Mantisbt

Status
Vendor
CVE Published:
17 June 2021

What is CVE-2021-33557?

A cross-site scripting (XSS) vulnerability has been identified in MantisBT, impacting versions earlier than 2.25.2. This issue arises from the improper handling of output in the manage_custom_field_edit_page.php file, specifically pertaining to the return parameter. Attackers can exploit this vulnerability to inject malicious code into a hidden input field, potentially leading to unauthorized actions and data breaches within the application. It is crucial to apply recommended updates to prevent exploitation.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.