HomeCVE Intelligence › CVE-2026-62944
CVSS 7.5 HIGH Vulnerability

CVE-2026-62944: MantisBT: Stored XSS in print_all_bug_page_word.php

A missing output encoding call in print_all_bug_page_word.php allows any authenticated user to inject arbitrary HTML into an IMG tag's *altattribute via an image attachment with a crafted filename such as probe." onload…

7.5CVSS Score
HIGHSeverity
NOCISA KEV
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-62944
Vendorcomposer
Affected Productmantisbt/mantisbt
Vulnerability TypeVulnerability
CVSS Score7.5 (HIGH)
Actively Exploited❌ No known exploitation
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories)

🔬 Technical Analysis

A missing output encoding call in print_all_bug_page_word.php allows any authenticated user to inject arbitrary HTML into an IMG tag's *alt* attribute via an image attachment with a crafted filename such as probe." onload="alert(1). When any user views the HTML export page (print_all_bug_page_word.php?type_page=html&export=1), the rendered IMG tag becomes , breaking out of the alt attribute.

Impact

Cross-site scripting. Impact is limited by MantisBT's Content Security Policy.

Patches

• https://github.com/mantisbt/mantisbt/commit/bdd0e364f62759de272dfd4c89b4f51d27be9daa

Workarounds

None

Resources

• https://mantisbt.org/bugs/view.php?id=37234

Credits

MantisBT thanks the [Dracosec Research Limited](https://dracosec.tech/) team (Chris Chan, Krecendo Hui, William Lam) f

🎯 Known Indicators of Compromise

{"type":"sha1","value":"bdd0e364f62759de272dfd4c89b4f51d27be9daa","confidence_score":0.9,"first_seen":"2026-07-15","source_count":1} {"type":"url","value":"https://github.com/mantisbt/mantisbt/commit/bdd0e364f62759de272dfd4c89b4f51d27be9daa","confidence_score":0.82,"first_seen":"2026-07-15","source_count":1} {"type":"url","value":"https://mantisbt.org/bugs/view.php?id=37234","confidence_score":0.82,"first_seen":"2026-07-15","source_count":1} {"type":"url","value":"https://dracosec.tech/)","confidence_score":0.82,"first_seen":"2026-07-15","source_count":1} {"type":"domain","value":"mantisbt.org","confidence_score":0.75,"first_seen":"2026-07-15","source_count":1}

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2026-62944 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence