print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries for bugs that would otherwise be restricted.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.debian.org/security/2002/dsa-153 | patch vendor advisory |
http://marc.info/?l=bugtraq&m=102978873620491&w=2 | mailing list |
http://mantisbt.sourceforge.net/advisories/2002/2002-02.txt | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/9898 | vdb entry |
http://www.securityfocus.com/bid/5515 | vdb entry patch vendor advisory |