Hi,
I found a vulnerability in the current stable release of MantisBT (1.2.19). Using this vulnerability, an unauthenticated user can hijack another user account. Please provide an email address where I can send the vulnerability informations. I will release the technical details of the attack on my blog 90 days after this post.
Thank you,
Pier-Luc Maltais
Mantis 1.2.19 vulnerability
Moderators: Developer, Contributor
Re: Mantis 1.2.19 vulnerability
Please follow the instructions at https://www.mantisbt.org/wiki/doku.php/ ... y_problems
Re: Mantis 1.2.19 vulnerability
Mr. Pier-Luc Maltais , Isn't it would be better if you share your vulnerability information here?
Thanks
Thanks
Re: Mantis 1.2.19 vulnerability
Well, not sure, Just want to see the things 

Re: Mantis 1.2.19 vulnerability
You can now, https://www.mantisbt.org/bugs/view.php?id=19384Rez wrote:Just want to see the things