View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0032931 | mantisbt | security | public | 2023-09-14 02:16 | 2023-10-13 12:56 |
Reporter | nhchoudhary | Assigned To | dregad | ||
Priority | high | Severity | major | Reproducibility | always |
Status | closed | Resolution | duplicate | ||
Product Version | 2.25.6 | ||||
Summary | 0032931: Formula Injection via the Report Issue functionality | ||||
Description | The application allowed users to input data in the format of formulas and export that data to a spreadsheet, where those formulas would | ||||
Steps To Reproduce | Steps to reproduce:
| ||||
Tags | No tags attached. | ||||
Thanks reporting the problem We will look into it as soon as possible. In the future, please always report security issues as private, following our guidelines https://mantisbt.org/wiki/doku.php/mantisbt:handling_security_problems |
|
This looks like the same problem as 0029130 (CVE-2021-43257). Can you please confirm what is the status of |
|
This is resolved after solution applied from https://www.mantisbt.org/bugs/view.php?id=29130 Please close this ticket. |
|
Thanks for the feedback. Closing as duplicate of 0029130 |
|