{"id":"CVE-2024-34081","aliases":["GHSA-wgx7-jp56-65mq"],"url":"https://o3.security/vulnerability/CVE-2024-34081","summary":"MantisBT Cross-site Scripting vulnerability","details":"Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when:\n- resolving or closing issues (bug_change_status_page.php) belonging to a project linking said custom field\n- viewing issues (view_all_bug_page.php) when the custom field is displayed as a column\n- printing issues (print_all_bug_page.php) when the custom field is displayed as a column\n\n### Impact\nCross-site scripting (XSS).\n\n### Patches\nhttps://github.com/mantisbt/mantisbt/commit/447a521aae0f82f791b8116a14a20e276df739be\n\n### Workarounds\nEnsure Custom Field Names do not contain HTML tags.\n\n### References\n- https://mantisbt.org/bugs/view.php?id=34432\n- This is related to CVE-2020-25830 (same root cause, different affected pages)\n","published":"2024-05-13T15:40:54.014Z","modified":"2026-08-12T03:51:45.413508783Z","cvss":{"score":6.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.26.2"}],"fix":{"url":"https://github.com/mantisbt/mantisbt/commit/447a521aae0f82f791b8116a14a20e276df739be","label":"mantisbt/mantisbt@447a521"},"references":[{"type":"WEB","url":"https://mantisbt.org/bugs/view.php?id=34432"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/34xxx/CVE-2024-34081.json"},{"type":"ADVISORY","url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-wgx7-jp56-65mq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34081"},{"type":"FIX","url":"https://github.com/mantisbt/mantisbt/commit/447a521aae0f82f791b8116a14a20e276df739be"},{"type":"PACKAGE","url":"https://github.com/mantisbt/mantisbt"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.413508783Z"}}