In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade mantisbt/mantisbt to version 2.28.4 or higher.
mantisbt/mantisbt is a mantis bug tracker.
Affected versions of this package are vulnerable to Improper Input Validation via the mc_issue_update process in the SOAP and REST APIs. An attacker can inject unauthorized TIME_TRACKING and REMINDER notes by supplying a crafted note_type parameter, which is not properly validated for user authorization. This can result in the injection of fake billable hours into billing reports or the creation of unauthorized REMINDER notes, potentially corrupting billing data and project management decisions. This is only exploitable if the attacker has UPDATER access and, for billing data manipulation, a higher access level than the configured time tracking view threshold.