CVE-2022-33910: XSS
An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or an admin clicks on the attachment, filedownload.php opens the SVG document in a browser tab instead of downloading it as a file, causing the JavaScript code to execute.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-33910?
CVE-2022-33910 is an XSS vulnerability in MantisBT before version 2.25.5.
How does CVE-2022-33910 affect MantisBT?
CVE-2022-33910 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes in MantisBT.
How can remote attackers exploit CVE-2022-33910?
Remote attackers can exploit CVE-2022-33910 by tricking a user or admin into clicking on a crafted SVG document attachment, which will be opened in a browser tab instead of being downloaded, allowing the execution of malicious JavaScript.
What is the severity of CVE-2022-33910?
CVE-2022-33910 has a severity rating of medium with a CVSS score of 5.4.
How can I fix CVE-2022-33910 in MantisBT?
To fix CVE-2022-33910, upgrade MantisBT to version 2.25.5 or higher.