Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g582-8vwr-68h2

Опубликовано: 03 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

MantisBT unauthorized disclosure of private project column configuration

Impact

Due to insufficient access-level checks, any non-admin user having access to manage_config_columns_page.php (typically project managers having MANAGER role) can use the Copy From action to retrieve the columns configuration from a private project they have no access to.

Access to the reverse operation (Copy To) is correctly controlled, i.e. it is not possible to alter the private project's configuration.

Patches

The vulnerability will be fixed in MantisBT version 2.27.2.

Workarounds

None

Credits

Thanks to d3vpoo1 for reporting the issue.

Пакеты

Наименование

mantisbt/mantisbt

composer
Затронутые версииВерсия исправления

< 2.27.2

2.27.2

EPSS

Процентиль: 11%
0.00037
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 4.3
nvd
3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access to manage_config_columns_page.php can use the Copy From action to retrieve the columns configuration from a private project they have no access to. This issue is fixed in version 2.27.2.

CVSS3: 4.3
debian
3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...

EPSS

Процентиль: 11%
0.00037
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-285