PT-2002-2119 · Mantis · Mantis

Published

2002-10-04

·

Updated

2017-10-10

·

CVE-2002-1116

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Mantis versions 0.17.4a and earlier
Description: The issue concerns the "View Bugs" page, specifically the view all bug page.php file, which incorrectly includes summaries of private bugs. This affects users without access to any projects, potentially exposing sensitive information.
Recommendations: For Mantis versions 0.17.4a and earlier, as a temporary workaround, consider restricting access to the view all bug page.php file until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1116
DSA-161

Affected Products

Mantis