PT-2002-2113 · Mantis · Mantis

Published

2002-09-10

·

Updated

2016-10-18

·

CVE-2002-1110

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Mantis versions 0.17.2 and earlier
Description: The issue allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, for example, to the "account update.php" endpoint, when running without magic quotes gpc enabled.
Recommendations: For Mantis versions 0.17.2 and earlier, consider disabling the account update functionality until a patch is available, and ensure magic quotes gpc is enabled to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1110
DSA-153

Affected Products

Mantis