An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| mantisbt/mantisbt(Packagist) | 0 | 2.25.3 | N/A |
CVSS Metrics