Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Sat, 17 Jan 2015 01:01:55 +0100
From: Damien Regad <>
Subject: CVE-2014-9572: Improper Access Control in install.php


Please update CVE-2014-9572 with the information below


The vulnerability exists due to insufficient access restrictions to the 
installation script "/[admin]/install.php" when HTTP GET "install" 
parameter is set to "4". A remote unauthenticated attacker can access 
the installation script and obtain database access credentials, which 
are stored in plain text in hidden form fields.

An attacker can use the following URL to access the page and obtain 
database credentials (login and password) in plaintext:

http://mantis/[admin]/install.php?install=4 [^]

Note, that "[admin]" in the URL is changed by default during 
installation. Therefore, the attacker must know the location of the 
administrative interface in order to perform the attack. However, admin 
panel URL can be bruteforced or predicted in many cases.

Affected versions:
- <= 1.2.19
- <= 1.3.0-beta.1

Fixed in versions:
- 1.2.19 (not yet released)
- 1.3.0-beta.2 (not yet released)

See Github [1]

This vulnerability was reported [2] by High-Tech Bridge Security 
Research Lab (, via advisory ID HTB23243 [3].
The issue was fixed by Damien Regad (MantisBT Developer).

Further details available in our issue tracker [4]

[1] (1.2.x) (1.3.x)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.