CVE-2006-6574: Medium severity mantis mantis vulnerability
Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6574?
CVE-2006-6574 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2006-6574?
To fix CVE-2006-6574, upgrade to Mantis version 1.1.0a2 or later, which includes per-item access control for Issue History.
What systems are affected by CVE-2006-6574?
CVE-2006-6574 affects Mantis versions prior to 1.1.0a2, including versions 1.0.0 and its release candidates.
What kind of vulnerabilities does CVE-2006-6574 represent?
CVE-2006-6574 represents an access control vulnerability that allows unauthorized information access.
Can CVE-2006-6574 lead to any other types of attacks?
While CVE-2006-6574 primarily represents information disclosure, exploiting it could potentially aid in further attacks due to leaked sensitive information.