Vulnerabilities > Mantisbt > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-08-21 CVE-2019-15074 Cross-site Scripting vulnerability in Mantisbt
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename.
network
low complexity
mantisbt CWE-79
critical
9.6