VDB
Sign up
HIGH

GHSA-p6fr-rxq7-xcg8

MantisBT Vulnerable to Stored XSS in File Download

Quick fix

GHSA-p6fr-rxq7-xcg8 — mantisbt/mantisbt: upgrade to the fixed version with the command below.

composer require mantisbt/mantisbt:^2.28.2

Details

Using *show_inline=1* parameter and a valid *file_show_inline_token* CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment.

### Impact Cross-site scripting

### Patches - 26647b2e68ba30b9d7987d4e03d7a16416684bc2

### Workarounds None

### Credits Thanks to siunam (Tang Cheuk Hei) for discovering and responsibly reporting the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mantisbt/mantisbt
Introduced in: 0Fixed in: 2.28.2
Fixcomposer require mantisbt/mantisbt:^2.28.2

References