Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crmx-4p49-46m2

Опубликовано: 11 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked

MantisBT allows a bugnote author to access the note's Revisions page after losing access to the parent private issue.

Impact

Disclosure of the private Issue's Id and Summary. The bugnote full revision body remains secure.

Patches

  • 71df1f67e05b2050cd4bd87839e6cc13747cf03f

Workarounds

None

Credits

Thanks to Vishal Shukla for discovering and responsibly reporting the issue.

Пакеты

Наименование

mantisbt/mantisbt

composer
Затронутые версииВерсия исправления

<= 2.28.1

2.28.2

EPSS

Процентиль: 30%
0.00372
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-200

Связанные уязвимости

nvd
3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to access the note's Revisions page after losing access to the parent private issue. This issue has been fixed in version 2.28.2.

debian
3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Version ...

EPSS

Процентиль: 30%
0.00372
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-200