CVE-2006-6515
Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged rol
Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact and attack vectors, possibly related to frequency of reminders.
HIGH · CVSS 10
EPSS 0.00376
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0