First published: Thu Jun 17 2021(Updated: )
An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | <2.25.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-33557.
The severity of CVE-2021-33557 is medium.
The affected software for CVE-2021-33557 is MantisBT before 2.25.2.
CVE-2021-33557 is an XSS issue in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
To fix CVE-2021-33557, you should update MantisBT to version 2.25.2 or later.