CVE-2026-40597 | mantisbt Mantis Bug Tracker up to 2.28.1 Attachment file_create_finfo cross site scripting (GHSA-9c3j-xm6v-j7j3)
A vulnerability classified as problematic was found in mantisbt Mantis Bug Tracker up to 2.28.1. This affects the function file_create_finfo of the component Attachment Handler. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-40597. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.