Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MantisBT 安全漏洞
Vulnerability Description
MantisBT是MantisBT(Mantisbt)团队的一套基于Web的开源缺陷跟踪系统。该系统以Web操作的形式提供项目管理及缺陷跟踪服务。 MantisBT 2.25.3之前版本存在安全漏洞,该漏洞源于CSV API 中缺乏对公式元素的中和。当用户在 Excel 中打开 csv_export.php 生成的 CSV 文件时,非特权攻击者可以利用该漏洞执行代码或获取信息。
CVSS Information
N/A
Vulnerability Type
N/A