MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
| Software | From | Fixed in |
|---|---|---|
mantisbt / mantisbt
|
2.0.0 | 2.22.1 |
mantisbt / mantisbt
|
1.0.0 | 1.3.20 |