Vulnerability Description
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call in current_user_api.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mantisbt | Mantisbt | <= 2.10.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103065Third Party AdvisoryVDB Entry
- https://github.com/mantisbt/mantisbt/commit/de686a9e6d8c909485b87ca09c8f912bf830
- https://mantisbt.org/bugs/view.php?id=23921Vendor Advisory
- http://www.securityfocus.com/bid/103065Third Party AdvisoryVDB Entry
- https://github.com/mantisbt/mantisbt/commit/de686a9e6d8c909485b87ca09c8f912bf830
- https://mantisbt.org/bugs/view.php?id=23921Vendor Advisory
FAQ
What is CVE-2018-6526?
CVE-2018-6526 is a vulnerability with a CVSS score of 5.3 (MEDIUM). view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call i...
How severe is CVE-2018-6526?
CVE-2018-6526 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-6526?
Check the references section above for vendor advisories and patch information. Affected products include: Mantisbt Mantisbt.