Логотип exploitDog
bind:CVE-2023-22476
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-22476

Количество 3

Количество 3

nvd логотип

CVE-2023-22476

почти 3 года назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions prior to 2.25.6, due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can access to the _Summary_ field of private Issues (i.e. having Private view status, or belonging to a private Project) via a crafted `bug_arr[]` parameter in *bug_actiongroup_ext.php*. This issue is fixed in version 2.25.6. There are no workarounds.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-22476

почти 3 года назад

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hf4x-6h87-hm79

почти 3 года назад

MantisBT may expose private issues' summaries to unauthorized users

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-22476

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions prior to 2.25.6, due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can access to the _Summary_ field of private Issues (i.e. having Private view status, or belonging to a private Project) via a crafted `bug_arr[]` parameter in *bug_actiongroup_ext.php*. This issue is fixed in version 2.25.6. There are no workarounds.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-22476

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-hf4x-6h87-hm79

MantisBT may expose private issues' summaries to unauthorized users

CVSS3: 4.3
0%
Низкий
почти 3 года назад

Уязвимостей на страницу