CVE-2008-4688: Infoleak
Published Oct 22, 2008
·Updated
core/stringapi.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.
Affected Software
13 affected components
Mantis Mantis<=1.1.3
Mantis Mantis=0.19.3
Mantis Mantis=0.19.4
Mantis Mantis=1.0.1
Mantis Mantis=1.0.2
Mantis Mantis=1.0.3
Mantis Mantis=1.0.4
Mantis Mantis=1.0.5
Mantis Mantis=1.0.6
Mantis Mantis=1.0.7
Mantis Mantis=1.0.8
Mantis Mantis=1.1.1
Mantis Mantis=1.1.2
Event History
Oct 22, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4688?
CVE-2008-4688 is considered a moderate severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2008-4688?
To address CVE-2008-4688, upgrade MantisBT to version 1.1.3 or later.
3
What specific issue does CVE-2008-4688 exploit?
CVE-2008-4688 exploits a lack of privilege checks in the core/string_api.php file, allowing unauthorized information access.
4
Which versions of MantisBT are affected by CVE-2008-4688?
CVE-2008-4688 affects MantisBT versions up to and including 1.1.2.
5
Can CVE-2008-4688 lead to sensitive data exposure?
Yes, CVE-2008-4688 can lead to sensitive data exposure by allowing attackers to discover issue titles and statuses.