CVE-2010-3303
MantisBT <1.2.3 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.3 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) a plugin name, related to manage_plugin_uninstall.php; (2) an enumeration value or (3) a String value of a custom field, related to core/cfdefs/cfdef_standard.php; or a (4) project or (5) category name to print_all_bug_page_word.php.
References (17)
Scores
EPSS
0.0039
EPSS Percentile
59.9%
Classification
CWE
CWE-79
Status
published
Affected Products (39)
mantisbt/mantisbt
< 1.2.2
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
... and 24 more
Timeline
Published
Oct 05, 2010
Tracked Since
Feb 18, 2026