Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.
Exploitability
AV:NAC:HAu:SImpact
C:NI:PA:N2.1/AV:N/AC:H/Au:S/C:N/I:P/A:N