CVE-2020-28413
Published on: 12/30/2020 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:23:26 PM UTC
Certain versions of Mantisbt from Mantisbt contain the following vulnerability:
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
- CVE-2020-28413 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
CVE-2020–28413 / Blind SQL Injection en Mantis Bug Tracker 2.24.3 API SOAP. | by EthicalHCOP | Dec, 2020 | Medium | Third Party Advisory ethicalhcop.medium.com text/html |
![]() |
Mantis Bug Tracker 2.24.3 SQL Injection ≈ Packet Storm | Exploit Third Party Advisory packetstormsecurity.com text/html |
![]() |
Related QID Numbers
- 690229 Free Berkeley Software Distribution (FreeBSD) Security Update for mantis (2dc8927b-54e0-11eb-9342-1c697a013f4b)
Exploit/POC from Github
Dicha vulnerabilidad se presentaba en la funcionalidad mc_project_get_users, y su detección es tan solo modificando y…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Mantisbt | Mantisbt | 2.24.3 | All | All | All |
Application | Mantisbt | Mantisbt | 2.24.3 | All | All | All |
- cpe:2.3:a:mantisbt:mantisbt:2.24.3:*:*:*:*:*:*:*:
- cpe:2.3:a:mantisbt:mantisbt:2.24.3:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2020-28413 MantisBT SQL注入漏洞分析 ift.tt/mPXrkZv ift.tt/UQp82ig | 2022-09-05 16:35:34 |