CVE-2008-4688

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
22/10/2008
Last modified:
09/04/2025

Description

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mantis:mantis:*:*:*:*:*:*:*:* 1.1.3 (including)
cpe:2.3:a:mantis:mantis:0.19.3:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.1.2:*:*:*:*:*:*:*