Show filters
115 Total Results
Displaying 31-40 of 115
Sort by:
Attacker Value
Unknown

CVE-2019-15715

Disclosure Date: October 09, 2019 (last updated November 27, 2024)
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
Attacker Value
Unknown

CVE-2019-15074

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed.
0
Attacker Value
Unknown

CVE-2018-16514

Disclosure Date: June 20, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-13055.
0
Attacker Value
Unknown

CVE-2018-9839

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying the 'm_id' parameter), any user with REPORTER access or above is able to view any private issue's details (summary, description, steps to reproduce, additional information) when cloning it. By checking the 'Copy issue notes' and 'Copy attachments' checkboxes and completing the clone operation, this data also becomes public (except private notes).
0
Attacker Value
Unknown

CVE-2018-17783

Disclosure Date: October 30, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.
0
Attacker Value
Unknown

CVE-2018-17782

Disclosure Date: October 30, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.
0
Attacker Value
Unknown

CVE-2018-13055

Disclosure Date: August 03, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO.
0
Attacker Value
Unknown

CVE-2018-14504

Disclosure Date: August 03, 2018 (last updated November 27, 2024)
An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with a crafted name (e.g., 'foobar" onclick="alert(1)').
0
Attacker Value
Unknown

CVE-2018-6526

Disclosure Date: February 02, 2018 (last updated November 26, 2024)
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call in current_user_api.php.
0
Attacker Value
Unknown

CVE-2018-6382

Disclosure Date: January 30, 2018 (last updated November 08, 2023)
MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parameter in a request to the 127.0.0.1 IP address. NOTE: the vendor disputes the significance of this report because server.php is intended to execute arbitrary SQL statements on behalf of authenticated users from 127.0.0.1, and the issue does not have an authentication bypass
0