CVE-2008-3331 describes a cross-site scripting (XSS) vulnerability in Mantis before version 1.1.2, specifically within the return_dynamic_filters.php component, allowing remote authenticated attackers to inject malicious web script or HTML via the filter_target parameter. This vulnerability has a CVSS score of 3.5, indicating a medium attack complexity and requiring user authentication, with a potential impact of partial integrity compromise. While not listed on the KEV catalog or Hot List, an ExploitDB entry (EDB-5657) exists, suggesting proof-of-concept code availability for XSS, code execution, and CSRF. Despite this, there is no evidence of active exploitation, and the vulnerability has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.1CPE matchmatch criteria | cpe:2.3:a:mantis:mantis:*:*:*:*:*:*:*:* | ||
0.9CPE matchmatch criteria | cpe:2.3:a:mantis:mantis:0.9:*:*:*:*:*:*:* | ||
0.9.0CPE matchmatch criteria | cpe:2.3:a:mantis:mantis:0.9.0:*:*:*:*:*:*:* | ||
0.9.1CPE matchmatch criteria | cpe:2.3:a:mantis:mantis:0.9.1:*:*:*:*:*:*:* | ||
0.10CPE matchmatch criteria | cpe:2.3:a:mantis:mantis:0.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.