S4E just found a high top 10 tcp port service scan
medium·Web Vulnerabilities·Updated Apr 25, 2025

CVE-2022-28508 Scanner

CVE-2022-28508 Scanner - Cross-Site Scripting vulnerability in MantisBT

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-28508
6.1
CVSS

An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

MantisBT is widely used by businesses and developers for tracking software bugs and project management. It provides a robust platform where users can report issues, track bug progress, and collaborate on solutions. MantisBT is open-source, making it adaptable and scalable for different organizational needs. The tool is popular for its user-friendly interface and comprehensive feature set that accommodates both small teams and large enterprises. Organizations use it to enhance project transparency and streamline issue resolution workflows. Many industries, including IT services, software development, and project management, rely on MantisBT to ensure efficient issue tracking and project completion.

Cross-Site Scripting (XSS) is a vulnerability that occurs when an application includes untrusted data in a web page without proper validation. It allows attackers to execute arbitrary scripts in the victim's browser, which can lead to session hijacking, defacement, or redirecting users to malicious sites. This vulnerability typically impacts websites that fail to properly filter user input. It poses a substantial security threat by enabling attackers to manipulate site content or behavior. Detecting XSS vulnerabilities is crucial for safeguarding user data and maintaining website integrity. Various mitigation strategies, like input validation and contextual escaping, are employed to prevent XSS attacks.

The vulnerability in MantisBT lies within the 'browser_search_plugin.php' endpoint, where the 'type' parameter is not adequately sanitized. Attackers can craft URLs that include malicious scripts through this parameter. When executed, these scripts can perform actions like theft of credentials or posing as legitimate web content. The endpoint’s failure to sanitize inputs allows for script injection that can severely impact user data security. Attack vectors commonly involve tricking users into visiting a specially crafted URL. The exploitation of this vulnerability is facilitated by the lack of validation checks on input parameters within the application.

Exploiting this vulnerability can lead to critical security implications for affected users and systems. Attackers may gain unauthorized access to sensitive data, such as user sessions, personal information, and authentication details. The execution of arbitrary JavaScript can result in session hijacking, where an attacker takes control of a user's session and potentially impersonates them on the site. Users may be exposed to additional risks like phishing attacks, where they are redirected to fraudulent websites designed to steal personal information. Overall, the impact of this vulnerability can undermine user trust and compromise the integrity of the application.

REFERENCES

Solution Advice
  • Upgrade MantisBT to version 2.25.2 or later to patch the vulnerability.
  • If upgrading is not feasible immediately, restrict access to the vulnerable endpoint: browser_search_plugin.php.
  • Implement input validation and sanitization to prevent script injections through user inputs.
  • Regularly review and update the application's security settings to adhere to industry best practices.
  • Educate users about the risks of phishing attacks and encourage cautious engagement with unfamiliar links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.