VYPR
Medium severity5.3OSV Advisory· Published Feb 2, 2018· Updated Jun 17, 2026

CVE-2018-6526

CVE-2018-6526

Description

view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call in current_user_api.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Range: release-1.2.0a1, release-1.2.0a2, release-1.2.0a3, …
  • Mantisbt/Mantisbt2 versions
    cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*range: <=2.10.0
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.