Critical 9.3 CVSS Auth Bypass and XSS Flaws Hit MantisBT
ID: 62f3a7ae-094f-5a5d-a2d0-c34e4547b437
STIX ID: report--62f3a7ae-094f-5a5d-a2d0-c34e4547b437
Feed Name: securityonline.info
Security researchers disclosed three vulnerabilities in MantisBT, including a critical authentication bypass (CVE-2026-30849, CVSS 9.3) that allows attackers to authenticate via the SOAP API on MySQL-compatible backends and two high-severity HTML injection/XSS issues (CVE-2026-33517, CVE-2026-33548); all versions up to 2.28.1 are affected and administrators are urged to apply patches or temporary mitigations such as disabling the SOAP API and sanitizing timeline/history entries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
