Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4x5-gvx6-3rwc

Опубликовано: 11 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API

Impact

MantisBT allows an authenticated user to upload attachments to private Issues they are not authorized to access.

Patches

  • b262b4d2835b81394d75356dead66e52a6275206

Workarounds

None.

Credits

Thanks to Vishal Shukla for discovering and responsibly reporting the issue.

Пакеты

Наименование

mantisbt/mantisbt

composer
Затронутые версииВерсия исправления

<= 2.28.1

2.28.2

EPSS

Процентиль: 16%
0.00248
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.

CVSS3: 4.3
debian
3 месяца назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Version ...

EPSS

Процентиль: 16%
0.00248
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284