Problems have been identified in the handling of some types of input by Mantis. Because of this, an attacker may be able to execute code in the browser of target victims. Specific details concerning the issue are not available. Like any cross-site scripting attack, this issue is conjectured to require the click of a malicious link by a target victim, which in turn executes script code in the security context of the site hosting the vulnerable software.
Problems have been identified in the handling of some types of input by Mantis. Because of this, an attacker may be able to execute code in the browser of target victims. Specific details concerning the issue are not available. Like any cross-site scripting attack, this issue is conjectured to require the click of a malicious link by a target victim, which in turn executes script code in the security context of the site hosting the vulnerable software.