5
CVSSv2

CVE-2008-4688

Published: 22/10/2008 Updated: 10/02/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

core/string_api.php in Mantis prior to 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote malicious users to discover an issue's title and status via a request with a modified issue number.

Vulnerable Product Search on Vulmon Subscribe to Product

mantis mantis 1.0.7

mantis mantis 1.0.6

mantis mantis 0.19.3

mantis mantis 1.0.8

mantis mantis 1.0.1

mantis mantis 0.19.4

mantis mantis 1.0.3

mantis mantis 1.0.2

mantis mantis 1.1.2

mantis mantis 1.0.5

mantis mantis 1.0.4

mantis mantis 1.1.1

mantis mantis