CVE-2014-9506
04.01.2015, 21:59
MantisBT before 1.2.18 does not properly check permissions when sending an email that indicates when a monitored issue is related to another issue, which allows remote authenticated users to obtain sensitive information about restricted issues.Enginsight
Vendor | Product | Version |
---|---|---|
mantisbt | mantisbt | 𝑥 ≤ 1.2.17 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References