CVE-2018-6382

LOW

MantisBT 2.10.0 - SQL Injection via ADOdb server.php sql Parameter

Title source: llm
STIX 2.1

Description

MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parameter in a request to the 127.0.0.1 IP address. NOTE: the vendor disputes the significance of this report because server.php is intended to execute arbitrary SQL statements on behalf of authenticated users from 127.0.0.1, and the issue does not have an authentication bypass

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://mantisbt.org/bugs/view.php?id=23908

Scores

CVSS v3 3.3
EPSS 0.0053
EPSS Percentile 41.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
mantisbt/mantisbt 2.10.0
Published Jan 30, 2018
Tracked Since Feb 18, 2026