CVE-2017-6958: Mantisbt Source Integration

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by crafting any valid parameter.

Affected products

  • Mantisbt Source Integration: up to and including 2.0.1

Published 2017-03-17. Last modified 2026-06-17.