An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.
References
Link | Resource |
---|---|
http://github.com/mantisbt/mantisbt/commit/5595c90f11c48164331a20bb9c66098980516e93 | Patch Third Party Advisory |
http://github.com/mantisbt/mantisbt/commit/9de20c09e5a557e57159a61657ce62f1a4f578fe | Patch Third Party Advisory |
https://mantisbt.org/bugs/view.php?id=27039 | Exploit Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2020-09-30 21:15
Updated : 2024-02-28 18:08
NVD link : CVE-2020-25781
Mitre link : CVE-2020-25781
CVE.ORG link : CVE-2020-25781
JSON object : View
Products Affected
mantisbt
- mantisbt
CWE
CWE-862
Missing Authorization