CVE-2020-25288: XSS
Published Sep 30, 2020
·Updated
An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular Expression property is used, improper escaping of the corresponding form input's pattern attribute allows HTML injection and, if CSP settings permit, execution of arbitrary JavaScript.
Affected Software
2 affected componentsFixes available
MantisBT mantisbt<2.24.3
composer/mantisbt/mantisbt>=2.23.0<2.24.3
2.24.3
Remediation
Patch Available
Event History
Sep 30, 2020
CVE Published
via MITRE·08:26 PM
Data Sourced
via MITRE·08:26 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:29 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-25288.
2
What is the severity level of CVE-2020-25288?
The severity level of CVE-2020-25288 is medium.
3
What is the affected software for CVE-2020-25288?
The affected software for CVE-2020-25288 is MantisBT before version 2.24.3.
4
How can this vulnerability be exploited?
This vulnerability can be exploited through HTML injection and potential execution of arbitrary code if CSP settings permit.
5
Is there a fix available for CVE-2020-25288?
Yes, the fix for CVE-2020-25288 can be found in MantisBT version 2.24.3.