CVE-2022-28508
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return param
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
MEDIUM · CVSS 6.1
EPSS 0.07116
Schedule remediation
- EPSS percentile: top 8% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0