Executive brief
MantisBT, a popular open-source bug tracking system, is vulnerable to a security flaw where malicious code can be hidden within custom text fields. If an attacker with basic reporting privileges saves a specially crafted message, it could allow them to hijack the sessions of other users, including administrators, when they view the affected ticket. This could lead to unauthorized access to sensitive project data or full control over the tracking system.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in MantisBT due to improper escaping of textarea-type custom field contents in the Update Issue page (bug_update_page.php). An authenticated attacker with low-level bug reporting permissions can inject malicious HTML or JavaScript into these fields. When an administrator or another user views the bug edit form, the payload executes in their browser context. This can result in session hijacking and full project data access. The vulnerability is mitigated by default Content-Security Policy (CSP) settings, but remains exploitable if CSP is disabled or insufficiently restrictive. A fix is available in version 2.28.2.
Affected products
- MantisBT MantisBT <= 2.28.1
Timeline
- 2026-05-09: disclosed
- 2026-05-11: advisory: GitHub Advisory published
- 2026-05-20: advisory: NVD published