MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| mantisbt/mantisbt(Packagist) | 0 | 1.3.20 | N/A |
| mantisbt/mantisbt(Packagist) | 2.0.0 | 2.22.1 | N/A |
CVSS Metrics