Medium severity5.3NVD Advisory· Published Dec 30, 2020· Updated Jun 17, 2026
CVE-2020-28413
CVE-2020-28413
Description
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mantisbt/mantisbtPackagist | < 2.24.4 | 2.24.4 |
Affected products
3- MantisBT/MantisBTdescription
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/160750/Mantis-Bug-Tracker-2.24.3-SQL-Injection.htmlnvdExploitThird Party AdvisoryWEB
- ethicalhcop.medium.com/cve-2020-28413-blind-sql-injection-en-mantis-bug-tracker-2-24-3-api-soap-54238f8e046dnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-49w9-82cj-xr48ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28413ghsaADVISORY
- github.com/mantisbt/mantisbt/commit/3e37b4041bf76422541836a424ca71bc4a660247ghsaWEB
News mentions
0No linked articles in our index yet.