Mantis 2.18.0
6 November 2018
Mantis version 2.18.0 is now available (security release).
Upgrading to Mantis 2.18.0
Mantis 2.18.0 can be upgraded to (or installed) using any of Installatron's products. Use Installatron's optional Automatic Update feature to automatically apply Mantis updates as new versions are released, or use Installatron's Clone feature to duplicate an existing Mantis install to test the 2.18.0 upgrade prior to applying it live. Get started managing your Mantis installations with Installatron
What's New in Mantis 2.18.0
2.18.0
Highlights
- [code cleanup] Code Cleanup
- [plug-ins] Plugin Columns - Export CSV or Excel - PHP 7.2.7 - crash error 500 - Reason missing 2 argument in call
- [bugtracker] Changes to project_view_state and view_state to create only private projects
- [html] Missing fallback for "Open Sans" font
- [tagging] Error Creating Issue with new TAG
- [performance] Performance enhancements of string processing
2.17.2
Security
- [security] CVE-2018-17783: XSS in manage_filter_edit_page.php
- [security] CVE-2018-17782: XSS in manage_filter_page.php
2.17.1
Security
- [security] CVE-2018-16514: Reflected XSS in view_filters_page.php via core/filter_form_api.php
2.17.0
Highlights
- [relationships] relationship visibility in different project permission
- [tagging] Tag cannot be selected if a tag containing the text of that tag has already been selected
- [bugtracker] Late error message when trying to resolve issues
- [authorization] Wrong box visibility on My View page
- [administration] Please change a search option to manage users
- [api soap] mc_filter_search_issues can't filter by date
- [html] Inline image attachments should have their own container to prevent scrolling
- [administration] Search for a part of
- [api rest] Add function for creating a new project via REST
- [api rest] Add function for updating a project via REST
- [api rest] Add function to delete a project via REST API
- [ui] bug_actiongroup and custom bug_actiongroup don't provide the same user experience when displaying error message
- [ui] Footer displays behind sidebar on bug_actiongroup.php
- [authorization] Custom fields can be changed without having update_bug_threshold access rights
- [api soap] Add filter for the “last updated“ date in the soap api
- [administration] Impersonate User is offered for disabled users
2.16.1
Security
- [security] CVE-2018-14895: XSS in bug_actiongroup.php
2.16.0
Highlights
- [ui] Local copy of Open Sans font does not include Latin-ext characters
- [ui] Fonts are not rendered correctly in Windows clients
- [upgrade] Improve handling of unserialize errors when upgrading
- [ui] Font = Times News Roman after Upgrade from v2.7.0
- [installation] MantisBT on Windows - Check for php_fileinfo.dll enabled on php.ini
- [performance] Unneeded information in Change Log and Roadmap
- [code cleanup] Code Cleanup
- [performance] Performance enhancement of config_get_global function
- [timeline] Missing display of events in Timeline if All Projects is selected
- [documentation] Documentation: PHP documentation link: "installation.php" -> "install.php"
- [documentation] Documentation: Admin Guide: Installation: Broken Link "Microsoft IIS", is now https://docs.microsoft.com/en-us/iis
- [upgrade] Error in upgrade process 1.2.17 --> 1.3.0
2.15.1
Security
- [security] CVE-2018-13055: Reflected XSS in view filters page
- [security] CVE-2018-14504: XSS in edit filters page
2.15.0
Highlights
- [filters] Cannot save private filter if not allowed to save shared filter
- [wiki] URL encoding precludes reasonable wiki root_namespace values
- [bugtracker] Incorrect issue status setting when changing status
- [api rest] Support create project versions via REST API
- [tagging] Exception Missing Class
- [security] Update-Blocker:User-ID instead of Realname 0024139 as due to security policy requirements which prohibit IDs in mails and masks
- [filters] show_user_realname_threshold is not considered when sorting by reporter or handler
- [ui] Selecting users is not easy if show_realname is set to ON
- [other] System warning if $g_log_destination = 'page' when using PHP 7.2
- [api soap] Error while querying for issue header with PHP 7.2
- [performance] Unneeded <meta> tag in <head> section
- [ui] $g_show_realname for making usernames private