An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.
References
Link | Resource |
---|---|
https://mantisbt.org/bugs/view.php?id=27039 | Exploit Patch Vendor Advisory |
http://github.com/mantisbt/mantisbt/commit/5595c90f11c48164331a20bb9c66098980516e93 | Patch Third Party Advisory |
http://github.com/mantisbt/mantisbt/commit/9de20c09e5a557e57159a61657ce62f1a4f578fe | Patch Third Party Advisory |
Configurations
Information
Published : 2020-09-30 14:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-25781
Mitre link : CVE-2020-25781
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
mantisbt
- mantisbt