First published: Wed Dec 30 2020(Updated: )
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | =2.24.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-28413 is medium.
SQL Injection can occur in CVE-2020-28413 through the API SOAP in the parameter "access" of the mc_project_get_users function.
MantisBT version 2.24.3 is affected by CVE-2020-28413.
Upgrade MantisBT to a version that is not affected by CVE-2020-28413.
You can find more information about CVE-2020-28413 at the following references: [link1](http://packetstormsecurity.com/files/160750/Mantis-Bug-Tracker-2.24.3-SQL-Injection.html), [link2](https://ethicalhcop.medium.com/cve-2020-28413-blind-sql-injection-en-mantis-bug-tracker-2-24-3-api-soap-54238f8e046d).