CVE-2026-44657
EPSS 0.07%MantisBT Vulnerable to Stored XSS in File Download
發布日:2026/5/11修改日:2026/5/11
描述
Using *show_inline=1* parameter and a valid *file_show_inline_token* CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. ### Impact Cross-site scripting ### Patches - 26647b2e68ba30b9d7987d4e03d7a16416684bc2 ### Workarounds None ### Credits Thanks to siunam (Tang Cheuk Hei) for discovering and responsibly reporting the issue.
受影響套件(1)
- Packagist/mantisbt/mantisbtfrom 0, < 2.28.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
參考連結(5)
- PATCHhttps://github.com/mantisbt/mantisbt
- WEBhttps://github.com/mantisbt/mantisbt/commit/26647b2e68ba30b9d7987d4e03d7a16416684bc2
- WEBhttps://github.com/mantisbt/mantisbt/security/advisories/GHSA-9c3j-xm6v-j7j3
- WEBhttps://github.com/mantisbt/mantisbt/security/advisories/GHSA-p6fr-rxq7-xcg8
- WEBhttps://mantisbt.org/bugs/view.php?id=37020