Vulnerability Description
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters, on some specific server configurations this could poison the cache, leading to cross-site scripting. This issue has been fixed in version 2.28.2.
Related Weaknesses (CWE)
References
- https://github.com/mantisbt/mantisbt/commit/b1ebc57763f104eb5f541b7b4d1ce6948168
- https://github.com/mantisbt/mantisbt/security/advisories/GHSA-6jh4-47v2-4g37
- https://mantisbt.org/bugs/view.php?id=37017
- https://mantisbt.org/bugs/view.php?id=37017
FAQ
What is CVE-2026-40598?
CVE-2026-40598 is a documented vulnerability. Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker ...
How severe is CVE-2026-40598?
CVSS scoring is not yet available for CVE-2026-40598. Check NVD for updates.
Is there a patch for CVE-2026-40598?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.