GHSA-w93w-rx52-24qh

Suggest an improvement
Source
https://github.com/advisories/GHSA-w93w-rx52-24qh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w93w-rx52-24qh/GHSA-w93w-rx52-24qh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w93w-rx52-24qh
Aliases
Published
2022-05-17T02:13:50Z
Modified
2025-06-09T22:42:04Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
MantisBT vulnerable to XSS via unsanitized filter field in manage_user_page.php
Details

An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-06-09T22:30:51Z",
    "nvd_published_at":  "2017-08-01T15:29:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / mantisbt/mantisbt

Package

Name
mantisbt/mantisbt
Purl
pkg:composer/mantisbt/mantisbt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.5.2

Affected versions

2.*
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.5.0
2.5.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w93w-rx52-24qh/GHSA-w93w-rx52-24qh.json"