CVE-2006-6515: Critical severity Mantis Mantis vulnerability
Mantis before 1.1.0a2 sets the default value of $gbugreminderthreshold to "reporter" instead of a more privileged role, which has unknown impact and attack vectors, possibly related to frequency of reminders.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6515?
CVE-2006-6515 does not have a widely assigned CVSS score, but its impact is unknown and could potentially affect the security of user reminders.
How do I fix CVE-2006-6515?
To mitigate CVE-2006-6515, upgrade MantisBT to version 1.1.0a2 or later where this vulnerability is addressed.
What versions are affected by CVE-2006-6515?
CVE-2006-6515 affects MantisBT versions prior to 1.1.0a2, including 1.0.0 through 1.0.6.
What is the root cause of CVE-2006-6515?
CVE-2006-6515 stems from MantisBT setting the default reminder access level to 'reporter' instead of a more privileged role.
Are there any known exploits for CVE-2006-6515?
As of now, there are no documented exploits for CVE-2006-6515, but its possible impacts remain uncertain.