CVE-2014-9506
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
04/01/2015
Last modified:
12/04/2025
Description
MantisBT before 1.2.18 does not properly check permissions when sending an email that indicates when a monitored issue is related to another issue, which allows remote authenticated users to obtain sensitive information about restricted issues.
Impact
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:* | 1.2.17 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://seclists.org/oss-sec/2014/q4/955
- http://secunia.com/advisories/62101
- http://www.debian.org/security/2015/dsa-3120
- https://www.mantisbt.org/bugs/changelog_page.php?version_id=191
- https://www.mantisbt.org/bugs/view.php?id=9885
- http://seclists.org/oss-sec/2014/q4/955
- http://secunia.com/advisories/62101
- http://www.debian.org/security/2015/dsa-3120
- https://www.mantisbt.org/bugs/changelog_page.php?version_id=191
- https://www.mantisbt.org/bugs/view.php?id=9885



