PT-2025-45718 · Packagist · Mantisbt/Mantisbt

Publicado

2025-11-03

·

Atualizado

2025-11-03

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Impact

Due to insufficient access-level checks, any non-admin user having access to manage config columns page.php (typically project managers having MANAGER role) can use the Copy From action to retrieve the columns configuration from a private project they have no access to.
Access to the reverse operation ( Copy To ) is correctly controlled, i.e. it is not possible to alter the private project's configuration.

Patches

The vulnerability will be fixed in MantisBT version 2.27.2.

Workarounds

None

Credits

Thanks to d3vpoo1 for reporting the issue.

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-G582-8VWR-68H2

Produtos afetados

Mantisbt/Mantisbt