Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown
CVE-2013-4460
Disclosure Date: January 10, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in account_sponsor_page.php in MantisBT 1.0.0 through 1.2.15 allows remote authenticated users to inject arbitrary web script or HTML via a project name.
0
Attacker Value
Unknown
CVE-2012-5523
Disclosure Date: November 16, 2012 (last updated October 05, 2023)
core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to obtain sensitive information by adding a note to a bug before losing permission to view that bug.
0
Attacker Value
Unknown
CVE-2012-5522
Disclosure Date: November 16, 2012 (last updated October 05, 2023)
MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.
0