6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters, on some specific server configurations this could poison the cache, leading to cross-site scripting. This issue has been fixed in version 2.28.2.
Basic Information
ID
CVE-2026-40598
Source
GitHub_M
Published
May 22, 2026 at 19:32
Affected Product
Vendor
mantisbt
Product
mantisbt
Version
< 2.28.2
Affected Versions
mantisbt mantisbt < 2.28.2