MEDIUM
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2
Published May 4, 2022
6.1
MEDIUMCVSS 3.1
EPSS 5.17%
Description
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-32950 Advisory
- https://github.com/YavuzSahbaz/CVE-2022-28508/blob/main/MantisBT%202.25.2%20XSS%20vulnurability x_refsource_MISCExploitThird Party Advisory
- https://github.com/advisories/GHSA-wfg2-2wmw-6894 Advisory
- https://mantisbt.org x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-28508
- https://sourceforge.net/projects/mantisbt x_refsource_MISCProductThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-32950 | Advisory | |
| https://github.com/YavuzSahbaz/CVE-2022-28508/blob/main/MantisBT%202.25.2%20XSS%20vulnurability | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/advisories/GHSA-wfg2-2wmw-6894 | Advisory | |
| https://mantisbt.org | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-28508 | ||
| https://sourceforge.net/projects/mantisbt | x_refsource_MISCProductThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 4, 2022
Updated Aug 3, 2024
Reserved Apr 4, 2022
Link CVE-2022-28508
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-32950 GHSA-WFG2-2WMW-6894 Assigner mitre
Published May 4, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-32950