Cross-Site Scripting Vulnerability in MantisBT by MantisBT
CVE-2021-33557
6.1MEDIUM
What is CVE-2021-33557?
A cross-site scripting (XSS) vulnerability has been identified in MantisBT, impacting versions earlier than 2.25.2. This issue arises from the improper handling of output in the manage_custom_field_edit_page.php file, specifically pertaining to the return parameter. Attackers can exploit this vulnerability to inject malicious code into a hidden input field, potentially leading to unauthorized actions and data breaches within the application. It is crucial to apply recommended updates to prevent exploitation.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
