CVE-2022-33910 is a medium-severity Cross-Site Scripting (XSS) vulnerability affecting MantisBT versions prior to 2.25.5. Attackers can exploit this by attaching specially crafted SVG documents to issue reports or bugnotes. When a user or administrator clicks on the attachment, the SVG is opened directly in the browser, executing embedded JavaScript code. While not actively exploited in the wild and lacking public exploit code, the vulnerability has a low attack complexity and could lead to limited data compromise and integrity issues. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.25.5CPE matchmatch criteria | cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.