MantisBT: master-2.25 03dd3722

Author Committer Branch Timestamp Parent
dregad dregad master-2.25 2021-05-15 05:43 master-2.25 5e15c2cb
Affected Issues  0028552: CVE-2021-33557: XSS in manage_custom_field_edit_page.php
Changeset

Fix XSS on manage_custom_field_edit_page.php

Thanks to Feras AL-KASSAR (SAP) en.feras@hotmail.com who reported
this vulnerability, which was discovered in the context of the EU
research project TESTABLE.

Unescaped output of 'return' parameter allows an attacker to inject code
into a hidden input field in the manage-custom-field-update-form.

Fixes 0028552, CVE-2021-33557

mod - manage_custom_field_edit_page.php Diff File