CVE-2020-28413: SQL Injection
Published Dec 30, 2020
·Updated
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mcprojectgetusers function through the API SOAP.
Affected Software
2 affected componentsFixes available
MantisBT mantisbt=2.24.3
composer/mantisbt/mantisbt<=2.24.3
2.24.4
Event History
Dec 30, 2020
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
DescriptionSeverity
May 24, 2022
Advisory Published
via GitHub·05:37 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-28413?
The severity of CVE-2020-28413 is medium.
2
How does SQL Injection occur in CVE-2020-28413?
SQL Injection can occur in CVE-2020-28413 through the API SOAP in the parameter "access" of the mc_project_get_users function.
3
What software versions are affected by CVE-2020-28413?
MantisBT version 2.24.3 is affected by CVE-2020-28413.
4
How can I fix the SQL Injection vulnerability in CVE-2020-28413?
Upgrade MantisBT to a version that is not affected by CVE-2020-28413.
5
Where can I find more information about CVE-2020-28413?
You can find more information about CVE-2020-28413 at the following references: [link1](http://packetstormsecurity.com/files/160750/Mantis-Bug-Tracker-2.24.3-SQL-Injection.html), [link2](https://ethicalhcop.medium.com/cve-2020-28413-blind-sql-injection-en-mantis-bug-tracker-2-24-3-api-soap-54238f8e046d).