CVE-2022-33910
An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports
An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or an admin clicks on the attachment, file_download.php opens the SVG document in a browser tab instead of downloading it as a file, causing the JavaScript code to execute.
MEDIUM · CVSS 5.4
EPSS 0.00251
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0