If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator does not remove the 'admin' directory (as recommended in the "Post-installation and upgrade tasks" section of the MantisBT Admin Guide), and the MySQL client has a localinfile setting enabled (in php.ini mysqli.allowlocal_infile, or the MySQL client config file, depending on the PHP setup), an attacker may take advantage of MySQL's "connect file read" feature to remotely access files on the MantisBT server.
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:mantisbt:mantisbt:2.5.2:*:*:*:*:*:*:*"
],
"vendor_product": "mantisbt:mantisbt",
"extracted_events": [
{
"introduced": "2.5.2"
},
{
"last_affected": "2.5.2"
}
]
}
]
}