CVE-2018-6382
LOWMantisBT 2.10.0 - SQL Injection via ADOdb server.php sql Parameter
Title source: llmDescription
MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parameter in a request to the 127.0.0.1 IP address. NOTE: the vendor disputes the significance of this report because server.php is intended to execute arbitrary SQL statements on behalf of authenticated users from 127.0.0.1, and the issue does not have an authentication bypass
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
http://archive.is/https:/mantisbt.org/bugs/view.php?id=23908
Issue Tracking, Vendor Advisory x_refsource_misc
https://mantisbt.org/bugs/view.php?id=23908
Scores
CVSS v3
3.3
EPSS
0.0053
EPSS Percentile
41.3%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-89
Status
published
Products (1)
mantisbt/mantisbt
2.10.0
Published
Jan 30, 2018
Tracked Since
Feb 18, 2026