CVE-2021-33557
An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the retu
An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
MEDIUM · CVSS 6.1
EPSS 0.0093
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0