PT-2002-2119 · Mantis · Mantis
Published
2002-10-04
·
Updated
2017-10-10
·
CVE-2002-1116
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Mantis versions 0.17.4a and earlier
Description:
The issue concerns the "View Bugs" page, specifically the view all bug page.php file, which incorrectly includes summaries of private bugs. This affects users without access to any projects, potentially exposing sensitive information.
Recommendations:
For Mantis versions 0.17.4a and earlier, as a temporary workaround, consider restricting access to the view all bug page.php file until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mantis