Description
MantisBT before 1.2.18 allows remote authenticated users to bypass the $g_download_attachments_threshold and $g_view_attachments_threshold restrictions and read attachments for private projects by leveraging access to a project that does not restrict access to attachments and a request to the download URL.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3120-1 | mantis security update |
EUVD |
EUVD-2014-8815 | MantisBT before 1.2.18 allows remote authenticated users to bypass the $g_download_attachments_threshold and $g_view_attachments_threshold restrictions and read attachments for private projects by leveraging access to a project that does not restrict access to attachments and a request to the download URL. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T13:33:12.665Z
Reserved: 2014-11-19T00:00:00.000Z
Link: CVE-2014-8988
No data.
Status : Modified
Published: 2014-11-24T15:59:14.373
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-8988
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD