Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Mantis | Mantis | 0.17.5 (including) | 0.17.5 (including) |
References