YavuzSahbaz/CVE-2022-28508

YavuzSahbaz/CVE-2022-28508

Releases0
Stars4
CVE-2022-28508

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM4.3 MEDIUM

An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.