MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference
Any authenticated user can inject arbitrary HTML via updating their account's font family.
Cross-site scripting. The injected payload will be reflected in every MantisBT page.
Leveraging another vulnerability (CSP bypass, see GHSA-9c3j-xm6v-j7j3), the attacker could achieve account takeover.
None
Thanks to siunam (Tang Cheuk Hei) for discovering and responsibly reporting the issue.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact(severity-tier estimate) | 80.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 80.00 |
VPI formula vpi-v1