Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h5q3-fjp4-2x7r

Опубликовано: 30 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

MantisBT vulnerable to information disclosure with user profiles

Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles.

Impact

Disclosure of private system profiles: Platform, OS, OS version, Description.

Patches

Workarounds

None

References

https://mantisbt.org/bugs/view.php?id=34640

Пакеты

Наименование

mantisbt/mantisbt

composer
Затронутые версииВерсия исправления

<= 2.26.3

2.26.4

EPSS

Процентиль: 59%
0.00377
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles. This vulnerability is fixed in 2.26.4.

CVSS3: 6.5
debian
больше 1 года назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a ...

EPSS

Процентиль: 59%
0.00377
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200