Description
MantisBT version 1.2.18 (and older versions) are affected by multiple security issues. All installations that are currently running any 1.2.x version are strongly advised to upgrade to MantisBT 1.2.19.
This release resolves 5 security issues:
- #17938/CVE-2014-9571: XSS in install.php
- #17939/CVE-2014-9572: Improper Access Control in install.php
- #17940/CVE-2014-9573: SQL Injection in manage_user_page.php
- #17984/CVE-2014-9624: CAPTCHA bypass
- #17997/CVE-2015-1042: URL redirection issue
Remediation
Upgrade to the latest version of MantisBT (these issues were fixed in version 1.2.19).
References
Related Vulnerabilities
WordPress Plugin Memphis Documents Library Arbitrary File Download (3.1.5)
WordPress Plugin The Crawl Rate Tracker 'sbtracking-chart-data.php' SQL Injection (2.0.2)
WordPress Plugin WP-Forum 'sendmail.php' SQL Injection (1.7.8)
WordPress Plugin Simple Events Calendar SQL Injection (1.3.5)
WordPress Plugin Advanced Woo Search Information Disclosure (1.99)