{"id":"GHSA-gg4j-279j-22ph","summary":"MantisBT allows cross-site scripting (XSS) via crafted filename","details":"The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed.","aliases":["CVE-2019-15074"],"modified":"2025-05-29T15:44:37.516740Z","published":"2022-05-24T16:54:23Z","database_specific":{"nvd_published_at":"2019-08-21T19:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-05-29T15:23:48Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15074"},{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/commit/9cee1971c498bbe0a72bca1c773fae50171d8c27"},{"type":"PACKAGE","url":"https://github.com/mantisbt/mantisbt"},{"type":"WEB","url":"https://mantisbt.org/bugs/view.php?id=25995"}],"affected":[{"package":{"name":"mantisbt/mantisbt","ecosystem":"Packagist","purl":"pkg:composer/mantisbt/mantisbt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.21.2"}]}],"versions":["2.10.0","2.10.1","2.11.0","2.11.1","2.12.0","2.12.1","2.12.2","2.13.0","2.13.1","2.13.2","2.14.0","2.15.0","2.15.1","2.16.0","2.16.1","2.17.0","2.17.1","2.17.2","2.18.0","2.18.1","2.19.0","2.19.1","2.20.0","2.20.1","2.21.0","2.21.1","2.3.0","2.3.1","2.3.2","2.3.3","2.4.0","2.4.1","2.4.2","2.5.0","2.5.1","2.5.2","2.6.0","2.7.0","2.7.1","2.8.0","2.8.1","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gg4j-279j-22ph/GHSA-gg4j-279j-22ph.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}