CVE-2019-15539
MEDIUM6.1EPSS 0.52%MantisBT XSS when uploading an attachment
Published: 5/24/2022Modified: 5/29/2025
Also known as:GHSA-p495-jrpq-p66g
Description
The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed when editing the document's page.
Affected packages (1)
- Packagist/mantisbt/mantisbtfrom 0, < 2.21.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |