{"id":"CVE-2020-35571","aliases":["GHSA-cvrm-cr3m-qj92"],"url":"https://o3.security/vulnerability/CVE-2020-35571","summary":"MantisBT XSS in manage_custom_field_update.php","details":"An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is not sanitized. This may be problematic depending on CSP settings.","published":"2021-02-22T03:15:14.183Z","modified":"2026-08-07T15:14:28.788650Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.25.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://mantisbt.org/bugs/view.php?id=27768"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:14:28.788650Z"}}