{"id":"CVE-2026-62944","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-62944","summary":"MantisBT: Stored XSS in print_all_bug_page_word.php","details":"A missing output encoding call in print_all_bug_page_word.php allows any authenticated user to inject arbitrary HTML into an IMG tag's *alt* attribute via an image attachment with a crafted filename such as `probe.\" onload=\"alert(1)`. \n\nWhen any user views the HTML export page (print_all_bug_page_word.php?type_page=html&export=1), the rendered IMG tag becomes `<img src=\"...\" alt=\"\" onload=\"alert(1)\" />`, breaking out of the alt attribute. \n\n### Impact\nCross-site scripting.\n\nImpact is limited by MantisBT's Content Security Policy.\n\n### Patches\n- https://github.com/mantisbt/mantisbt/commit/bdd0e364f62759de272dfd4c89b4f51d27be9daa\n\n### Workarounds\nNone\n\n### Resources\n- https://mantisbt.org/bugs/view.php?id=37234\n\n### Credits\nMantisBT thanks the [Dracosec Research Limited](https://dracosec.tech/) team (Chris Chan, Krecendo Hui, William Lam) for discovering and responsibly reporting the issue.","published":"2026-07-15T18:56:00Z","modified":"2026-07-15T19:11:50.363816Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.28.4"}],"fix":{"url":"https://github.com/mantisbt/mantisbt/commit/bdd0e364f62759de272dfd4c89b4f51d27be9daa","label":"mantisbt/mantisbt@bdd0e36"},"references":[{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h2wf-967x-gxvw"},{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/commit/bdd0e364f62759de272dfd4c89b4f51d27be9daa"},{"type":"PACKAGE","url":"https://github.com/mantisbt/mantisbt"},{"type":"WEB","url":"https://mantisbt.org/bugs/view.php?id=37234"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T19:11:50.363816Z"}}