CVE-2022-26144: XSS
Published Apr 13, 2022
·Updated
An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in managepluginpage.php and managepluginuninstall.php when a crafted plugin is installed.
Affected Software
2 affected componentsFixes available
MantisBT mantisbt<2.25.3
composer/mantisbt/mantisbt<=2.25.2
2.25.3
Event History
Apr 13, 2022
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
Description
Apr 14, 2022
Advisory Published
via GitHub·12:00 AM
Data Sourced
via GitHub·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-26144.
2
What is the severity level of CVE-2022-26144?
The severity level of CVE-2022-26144 is medium (6.1).
3
What is the affected software version of CVE-2022-26144?
The affected software version of CVE-2022-26144 is MantisBT before 2.25.3.
4
How does the vulnerability CVE-2022-26144 work?
The vulnerability CVE-2022-26144 is an XSS issue that allows execution of arbitrary code in manage_plugin_page.php and manage_plugin_uninstall.php if a crafted plugin is installed.
5
Is there a fix available for CVE-2022-26144?
Yes, the fix for CVE-2022-26144 is to upgrade to MantisBT version 2.25.3 or later.