An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on viewallbug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CSP settings allow it).
{
"github_reviewed": true,
"nvd_published_at": "2020-08-12T13:15:00Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-79"
],
"github_reviewed_at": "2025-05-29T15:45:07Z"
}