Description
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-4668 | core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T10:24:20.612Z
Reserved: 2008-10-22T00:00:00.000Z
Link: CVE-2008-4688
No data.
Status : Modified
Published: 2008-10-22T18:00:01.237
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-4688
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD