Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-938w-vx4g-p5w6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

EPSS

Процентиль: 90%
0.05344
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 17 лет назад

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

nvd
больше 17 лет назад

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

debian
больше 17 лет назад

core/string_api.php in Mantis before 1.1.3 does not check the privileg ...

EPSS

Процентиль: 90%
0.05344
Низкий

Дефекты

CWE-200