CVE-2008-4688
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issu
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.
MEDIUM · CVSS 5
EPSS 0.05344
Monitor
- EPSS percentile: top 10% of all CVEs by exploitation likelihood
Sigma rules0
YARA rules0