CVE-2014-9506: Infoleak
Published Jan 4, 2015
·Updated
MantisBT before 1.2.18 does not properly check permissions when sending an email that indicates when a monitored issue is related to another issue, which allows remote authenticated users to obtain sensitive information about restricted issues.
Affected Software
1 affected component
MantisBT mantisbt<=1.2.17
Event History
Jan 4, 2015
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9506?
CVE-2014-9506 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-9506?
To fix CVE-2014-9506, update MantisBT to version 1.2.18 or later.
3
What type of vulnerability is CVE-2014-9506?
CVE-2014-9506 is a permissions-related vulnerability that allows unauthorized access to sensitive information.
4
Which versions of MantisBT are affected by CVE-2014-9506?
MantisBT versions prior to 1.2.18, including 1.2.17 and earlier, are affected by CVE-2014-9506.
5
Who can exploit CVE-2014-9506?
Remote authenticated users can exploit CVE-2014-9506 to gain access to information about restricted issues.