MantisBT Custom Fields Management Pages Cross-Site Scripting Vulnerability Fixed by 1.2.20 and 1.3.0
Description
(:A cross-site scripting vulnerability was reported in MantisBT.:A remote attacker could exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.::This vulnerability stems from an improper user input validation for the "return URL" GPC parameter of Custom fields management pages.::A proof of concept is available.)