Vulnerabilities > Mantisbt > Mantisbt > 1.2.2

DATE CVE VULNERABILITY TITLE RISK
2021-01-29 CVE-2020-29604 Missing Authorization vulnerability in Mantisbt
An issue was discovered in MantisBT before 2.24.4.
network
low complexity
mantisbt CWE-862
4.0
2021-01-29 CVE-2020-29603 Insecure Storage of Sensitive Information vulnerability in Mantisbt
In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter, without having access to them.
network
low complexity
mantisbt CWE-922
4.0
2020-12-30 CVE-2020-35849 Incorrect Authorization vulnerability in Mantisbt
An issue was discovered in MantisBT before 2.24.4.
network
low complexity
mantisbt CWE-863
5.0
2020-09-30 CVE-2020-25830 Cross-site Scripting vulnerability in Mantisbt
An issue was discovered in MantisBT before 2.24.3.
network
mantisbt CWE-79
3.5
2020-09-30 CVE-2020-25781 Incorrect Authorization vulnerability in Mantisbt
An issue was discovered in file_download.php in MantisBT before 2.24.3.
network
low complexity
mantisbt CWE-863
4.0
2020-09-30 CVE-2020-25288 Cross-site Scripting vulnerability in Mantisbt
An issue was discovered in MantisBT before 2.24.3.
network
mantisbt CWE-79
3.5
2020-08-12 CVE-2020-16266 Cross-site Scripting vulnerability in Mantisbt
An XSS issue was discovered in MantisBT before 2.24.2.
network
mantisbt CWE-79
3.5
2020-03-19 CVE-2019-15539 Cross-site Scripting vulnerability in Mantisbt
The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename.
network
mantisbt CWE-79
4.3
2019-11-07 CVE-2013-1811 Improper Input Validation vulnerability in multiple products
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
network
low complexity
mantisbt debian CWE-20
4.0
2019-10-31 CVE-2013-1934 Cross-site Scripting vulnerability in multiple products
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.
3.5