Vulnerabilities
Vulnerable Software
Mantisbt:  >> Mantisbt  >> 2.24.4  Security Vulnerabilities
An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
CVSS Score
6.1
EPSS Score
0.009
Published
2021-06-17
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.
CVSS Score
8.1
EPSS Score
0.001
Published
2021-03-07


Contact Us

Shodan ® - All rights reserved