CVE-2022-28508: XSS
An XSS issue was discovered in browsersearchplugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
Other sources
An XSS issue was discovered in browsersearchplugin.php in MantisBT up to and including 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28508?
CVE-2022-28508 is an XSS vulnerability discovered in MantisBT before version 2.25.2.
What is the severity of CVE-2022-28508?
The severity of CVE-2022-28508 is medium, with a CVSS score of 6.1.
How does CVE-2022-28508 affect MantisBT?
CVE-2022-28508 allows an attacker to inject code into a hidden input field in MantisBT versions prior to 2.25.2.
How can I fix CVE-2022-28508?
To fix CVE-2022-28508, update MantisBT to version 2.25.2 or newer.
Where can I find more information about CVE-2022-28508?
You can find more information about CVE-2022-28508 on the MantisBT website or GitHub repository.