Mantis 1.2.19 vulnerability

General discussion of Mantis.

Moderators: Developer, Contributor

Post Reply
plmaltais
Posts: 1
Joined: 17 Feb 2015, 22:29

Mantis 1.2.19 vulnerability

Post by plmaltais »

Hi,

I found a vulnerability in the current stable release of MantisBT (1.2.19). Using this vulnerability, an unauthenticated user can hijack another user account. Please provide an email address where I can send the vulnerability informations. I will release the technical details of the attack on my blog 90 days after this post.

Thank you,

Pier-Luc Maltais
atrol
Site Admin
Posts: 8532
Joined: 26 Mar 2008, 21:37
Location: Germany

Re: Mantis 1.2.19 vulnerability

Post by atrol »

Please use Search before posting and read the Manual
Rez
Posts: 7
Joined: 09 Feb 2015, 00:34

Re: Mantis 1.2.19 vulnerability

Post by Rez »

Mr. Pier-Luc Maltais , Isn't it would be better if you share your vulnerability information here?
Thanks
atrol
Site Admin
Posts: 8532
Joined: 26 Mar 2008, 21:37
Location: Germany

Re: Mantis 1.2.19 vulnerability

Post by atrol »

Rez wrote:Isn't it would be better if you share your vulnerability information here?
Why? Is there any advantage for MantisBT users?
Please use Search before posting and read the Manual
Rez
Posts: 7
Joined: 09 Feb 2015, 00:34

Re: Mantis 1.2.19 vulnerability

Post by Rez »

Well, not sure, Just want to see the things :)
atrol
Site Admin
Posts: 8532
Joined: 26 Mar 2008, 21:37
Location: Germany

Re: Mantis 1.2.19 vulnerability

Post by atrol »

Rez wrote:Just want to see the things :)
Also attackers.
Still no advantage for MantisBT users ;-)
Please use Search before posting and read the Manual
Rez
Posts: 7
Joined: 09 Feb 2015, 00:34

Re: Mantis 1.2.19 vulnerability

Post by Rez »

:D
atrol
Site Admin
Posts: 8532
Joined: 26 Mar 2008, 21:37
Location: Germany

Re: Mantis 1.2.19 vulnerability

Post by atrol »

Rez wrote:Just want to see the things
You can now, https://www.mantisbt.org/bugs/view.php?id=19384
Please use Search before posting and read the Manual
Post Reply