CVE-2010-2574

EPSS 0.42%

MantisBT Cross-site Scripting vulnerability

Published: 5/14/2022Modified: 4/12/2025
Also known as:GHSA-74x7-mfvg-h2wf

Description

Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U

References (9)