First published: Wed Apr 13 2022(Updated: )
An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | <2.25.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-26144.
The severity level of CVE-2022-26144 is medium (6.1).
The affected software version of CVE-2022-26144 is MantisBT before 2.25.3.
The vulnerability CVE-2022-26144 is an XSS issue that allows execution of arbitrary code in manage_plugin_page.php and manage_plugin_uninstall.php if a crafted plugin is installed.
Yes, the fix for CVE-2022-26144 is to upgrade to MantisBT version 2.25.3 or later.