View Issue Details

IDProjectCategoryView StatusLast Update
0025775mantisbtbugtrackerpublic2019-05-20 22:21
Reportervboctor Assigned To 
PrioritynormalSeverityminorReproducibilityalways
Status newResolutionopen 
Product Version2.20.1 
Summary0025775: Error disclosing server file paths
Description

I noticed that when a plugin_lang_get() attempts to fetch a string that doesn't exist, the error message discloses the full path to the MantisBT instance on the server. I suspect this happens in other errors as well. See attached image.

TagsNo tags attached.

Activities

vboctor

vboctor

2019-05-20 22:21

manager  

Issue History

Date Modified Username Field Change
2019-05-20 22:21 vboctor New Issue
2019-05-20 22:21 vboctor File Added: lang_get_error_disclosing_path.png