CVE-2014-8553

Priority
Medium
Description
The mci_account_get_array_by_id function in api/soap/mc_account_api.php in
MantisBT before 1.2.18 allows remote attackers to obtain sensitive
information via a (1) mc_project_get_users, (2) mc_issue_get, (3)
mc_filter_get_issues, or (4) mc_project_get_issues SOAP request.
References
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needed)
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 17.10 (Artful Aardvark):DNE
More Information

Updated: 2018-06-26 04:57:07 UTC (commit 7799c934cca373482531a7b00e4dfe82302ceae5)