Damien Regad
65 exploits
Active since Jun 2012
MantisBT: Reflected XSS in Rendering Dynamic Custom Textarea Field
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API
MantisBT: Private Bugnote Attachment Content Leak via REST API
MantisBT: Stored XSS on Move Attachments Admin Page
MantisBT: Stored XSS in File Download
MantisBT is vulnerable to XSS and potential account takeover via user font family preference update
MantisBT <2.28.2 Attachments - Content Security Policy Bypass
MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page
MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Column
MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Values
CVSS 5.4
MantisBT <2.28.2 Private Issue Monitoring - Authorization Bypass
MantisBT authorization bypass allows continued access to self-uploaded attachments on private issues
MantisBT allows unauthorized users to upload attachments to restricted issues via REST API
CVSS 4.3
MantisBT Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked
MantisBT: Privilege Escalation from Manager to Administrator
MantisBT has Stored HTML Injection/XSS via Clone Issue Form
MantisBT: Authorization Bypass in Global Profile Creation
MantisBT < 1.2.9 - Unauthenticated Bug Report Copy Without Audit Log
MantisBT <1.2.19, <1.3.0-beta.2 - XSS
MantisBT <1.2.19, <1.3.0-beta.2 - SQL Injection
MantisBT <1.2.19, <1.3.0-beta.2 - XSS
CVSS 6.5
MantisBT < 1.2.19 - Authenticated Unauthorized File Download via Project Documentation Feature
CVSS 5.3
MantisBT < 1.2.19 - Cross-Site Scripting via manage_custom_field_edit_page.php Return Parameter
CVSS 6.1
MantisBT < 1.3.12 and 2.x < 2.5.2 - Cross-Site Scripting via Installation Script Variables
CVSS 6.1
MantisBT < 1.3.7 and 2.x < 2.2.1 - Cross-Site Scripting via 'action_type' Parameter
CVSS 6.1