Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-25781

Опубликовано: 30 сент. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 4
CVSS3: 4.3

Описание

An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

needs-triage

xenial

DNE

Показывать по

4 Medium

CVSS2

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 5 лет назад

An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.

CVSS3: 4.3
debian
больше 5 лет назад

An issue was discovered in file_download.php in MantisBT before 2.24.3 ...

CVSS3: 4.3
github
больше 3 лет назад

MantisBT unauthorized users able to access private files

4 Medium

CVSS2

4.3 Medium

CVSS3