CVE-2021-33557: XSS
Published Jun 17, 2021
·Updated
An XSS issue was discovered in managecustomfieldeditpage.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
Affected Software
2 affected componentsFixes available
MantisBT mantisbt<2.25.2
composer/mantisbt/mantisbt<=2.25.1
2.25.2
Event History
Jun 17, 2021
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
Description
May 24, 2022
Advisory Published
via GitHub·07:05 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-33557.
2
What is the severity of CVE-2021-33557?
The severity of CVE-2021-33557 is medium.
3
What is the affected software for CVE-2021-33557?
The affected software for CVE-2021-33557 is MantisBT before 2.25.2.
4
What is the description of CVE-2021-33557?
CVE-2021-33557 is an XSS issue in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
5
How can I fix the vulnerability CVE-2021-33557?
To fix CVE-2021-33557, you should update MantisBT to version 2.25.2 or later.