CVE-2011-3578
MantisBT <1.2.8 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter, related to bug_actiongroup_page.php, a different vulnerability than CVE-2011-3357.
References (18)
Scores
EPSS
0.0132
EPSS Percentile
79.7%
Classification
CWE
CWE-79
Status
published
Affected Products (28)
mantisbt/mantisbt
< 1.2.7
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
mantisbt/mantisbt
... and 13 more
Timeline
Published
Sep 21, 2011
Tracked Since
Feb 18, 2026