Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgg9-mmcg-8mxp

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью

Описание

MantisBT Incorrect Authorization in bug_actiongroup_page.php

An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (The target Issues can have Private view status, or belong to a private Project.)

Пакеты

Наименование

mantisbt/mantisbt

composer
Затронутые версииВерсия исправления

< 2.24.4

2.24.4

EPSS

Процентиль: 35%
0.00147
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
около 5 лет назад

An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (The target Issues can have Private view status, or belong to a private Project.)

CVSS3: 4.3
debian
около 5 лет назад

An issue was discovered in MantisBT before 2.24.4. Due to insufficient ...

EPSS

Процентиль: 35%
0.00147
Низкий

Дефекты

CWE-863