MantisBT vulnerable to XSS via unsanitized filter field in manage_user_page.php
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jun 9, 2025
Description
Published by the National Vulnerability Database
Aug 1, 2017
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Jun 9, 2025
Last updated
Jun 9, 2025
An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled.
References