VDB
Sign up
HIGH

GHSA-fvjf-68wh-rwp2

MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form

Quick fix

GHSA-fvjf-68wh-rwp2 — mantisbt/mantisbt: upgrade to the fixed version with the command below.

composer require mantisbt/mantisbt:^2.28.2

Details

When cloning an issue originating from a Project other than the current one, the clone form (bug_report_page.php) prepends the source Project name before the category selector without proper escaping, allowing an attacker able to to inject HTML if they can set the Project's name (which typically requires *manager* or *administrator* access level).

### Impact Cross-site scripting (XSS). This is mitigated by Content Security Policy which restricts scripts execution.

### Patches - df22697ae497ddd93f3d9132fdf4979db8d081cd

### Workarounds Make sure Project names do not contain any HTML tags.

### Credits Thanks to Vishal Shukla for discovering and responsibly reporting the issue.

The vulnerability was also identified and independently reported by @siunam321 (Tang Cheuk Hei), prior to this Advisory's publication.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mantisbt/mantisbt
Introduced in: 0Fixed in: 2.28.2
Fixcomposer require mantisbt/mantisbt:^2.28.2

References