CVE-2019-15539

MEDIUM6.1EPSS 0.52%

MantisBT XSS when uploading an attachment

Published: 5/24/2022Modified: 5/29/2025
Also known as:GHSA-p495-jrpq-p66g

Description

The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed when editing the document's page.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (4)