Page 1 of 1

BUG in Mantis - Forbidden in google chrome + firefox with Steps to reproduce when "user" is typed in that field.

Posted: 25 Nov 2019, 14:16
by Bart.1990
Hi Mantis BT team.
I have found following bug in MANTISBT.

When i a register a bug, everything works fine. But when the word "user" is in the field "Steps to reproduce" and you update / register the bug there will be an error 403 "FORBIDDEN"

We are testing an application with "users" so everytime we register a bug with steps (example): Click at "USER" ... then we got an error 403
I hope you can fix this as soon as possible.

Thank you,

Bart

Extra info:

MantisBT Version 2.22.1
Schema Version 209
PHP Version 7.2.24
Database Driver mysqli
Database Version, Description 10.3.17, 10.3.17-MariaDB

Re: BUG in Mantis - Forbidden in google chrome + firefox with Steps to reproduce when "user" is typed in that field.

Posted: 25 Nov 2019, 14:42
by dregad
This is not reproducible in a fresh installation of MantisBT 2.22.1.

Are you using any plugins or custom functions ? Was the MantisBT source code modified in any way ?

Re: BUG in Mantis - Forbidden in google chrome + firefox with Steps to reproduce when "user" is typed in that field.

Posted: 25 Nov 2019, 15:32
by Bart.1990
Hi,

Thanks for your message.

Same behaviour occurs with a brand new installation.

Steps:

Installed "Mantis BT" by using installatron (app installer from my webhost)
created new project ... name = Test..
create bug. summary = test / description test. With steps: 1. Select any territory 2. Click on Add User 3. Click on Show Me More

Account type = Administrator. But it will happen also with other user types like "developer"...

Bart