MantisBT: master-2.28 5cb4b469

Author Committer Branch Timestamp Parent
dregad dregad master-2.28 2026-05-03 13:00 master-2.28 86accbca
Affected Issues  0037099: CVE-2026-44655: XSS in move_attachments_page.php
Changeset

Fix XSS on move_attachments_page.php

Proper escaping of Project Name prevents HTML injection.

Fixes 0037099, GHSA-7mqj-8gj2-cg59

mod - admin/move_attachments_page.php Diff File