Vulnerabilities
Vulnerable Software
Mantisbt:  >> Mantisbt  >> 1.2.11  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in account_sponsor_page.php in MantisBT 1.0.0 through 1.2.15 allows remote authenticated users to inject arbitrary web script or HTML via a project name.
CVSS Score
3.5
EPSS Score
0.002
Published
2014-01-10
MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.
CVSS Score
5.5
EPSS Score
0.002
Published
2012-11-16
core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to obtain sensitive information by adding a note to a bug before losing permission to view that bug.
CVSS Score
5.5
EPSS Score
0.004
Published
2012-11-16


Contact Us

Shodan ® - All rights reserved