Vulnerability Description
MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parameter in a request to the 127.0.0.1 IP address. NOTE: the vendor disputes the significance of this report because server.php is intended to execute arbitrary SQL statements on behalf of authenticated users from 127.0.0.1, and the issue does not have an authentication bypass
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mantisbt | Mantisbt | 2.10.0 |
Related Weaknesses (CWE)
References
- http://archive.is/https:/mantisbt.org/bugs/view.php?id=23908Vendor Advisory
- https://mantisbt.org/bugs/view.php?id=23908Issue TrackingVendor Advisory
- http://archive.is/https:/mantisbt.org/bugs/view.php?id=23908Vendor Advisory
- https://mantisbt.org/bugs/view.php?id=23908Issue TrackingVendor Advisory
FAQ
What is CVE-2018-6382?
CVE-2018-6382 is a vulnerability with a CVSS score of 3.3 (LOW). MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parameter in a request to the 127.0.0.1 IP address. NOTE: the vendor disputes the sign...
How severe is CVE-2018-6382?
CVE-2018-6382 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-6382?
Check the references section above for vendor advisories and patch information. Affected products include: Mantisbt Mantisbt.