CVE-2011-2938

Mantisbt < 1.2.6 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script or HTML via a parameter, as demonstrated by the project_id parameter to search.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Net.Edit0r · textwebappsphp
https://www.exploit-db.com/exploits/36068

Scores

EPSS 0.1562
EPSS Percentile 94.6%

Classification

CWE
CWE-79
Status published

Affected Products (27)

mantisbt/mantisbt < 1.2.6
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
... and 12 more

Timeline

Published Sep 21, 2011
Tracked Since Feb 18, 2026