Junglewise Threat Intelligence

CVE-2026-52847: MantisBT reflected XSS in admin/install.php

CVE-2026-52847 · Severity: critical · CVSS 4 · Published 2026-07-15

Technologies: MantisBT, mantisbt/mantisbt (Packagist). Vendors: MantisBT, Packagist.

Executive brief

MantisBT, a popular open-source bug tracking system, contains a vulnerability in its installation component. An attacker can use this flaw to display fake login forms or redirect users to malicious websites. This could lead to the theft of administrator credentials or the spread of malware, potentially compromising the entire bug tracking system and its data.

Technical details

MantisBT 2.28.3 and earlier contains six reflected XSS injection points in /admin/install.php due to user-supplied parameters being echoed into HTML without escaping via the print_test_result() function. While a Content Security Policy (CSP) is present, it lacks a form-action directive, which allows attackers to bypass script execution restrictions to perform credential phishing via form injection, CSS-based UI manipulation, and <meta> tag open redirects. No authentication is required for exploitation. The vulnerability is addressed in version 2.28.4; a recommended workaround is to remove the /admin directory after installation.

Affected products

  • MantisBT MantisBT <= 2.28.3

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: patched: Fixed in version 2.28.4
  • 2026-07-15: advisory

References

Related threats