CVE-2020-28413: MantisBT SQL Injection via mc_project_get_users function
(updated )
In MantisBT 2.24.3, SQL Injection can occur in the parameter “access” of the mc_project_get_users function through the API SOAP.
References
Code Behaviors & Features
Detect and mitigate CVE-2020-28413 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →