First published: Mon Feb 22 2021(Updated: )
An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is not sanitized. This may be problematic depending on CSP settings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | <=2.24.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-35571 is medium.
CVE-2020-35571 affects MantisBT version up to and including 2.24.3.
The vulnerability type of CVE-2020-35571 is CWE-79 (Cross-site Scripting).
You can find the reference link for CVE-2020-35571 [here](https://mantisbt.org/bugs/view.php?id=27768).
To fix CVE-2020-35571, update MantisBT to version 2.24.4 or later.