MantisBT vulnerable to XSS via unescaped output in browser_search_plugin.php
Moderate severity
GitHub Reviewed
Published
May 5, 2022
to the GitHub Advisory Database
•
Updated Jun 9, 2025
Description
Published by the National Vulnerability Database
May 4, 2022
Published to the GitHub Advisory Database
May 5, 2022
Reviewed
Jun 9, 2025
Last updated
Jun 9, 2025
An XSS issue was discovered in browser_search_plugin.php in MantisBT up to and including 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
References