PT-2019-11173 · Mantisbt · Mantisbt
Mustafa Hasan
+1
·
Published
2019-06-06
·
Updated
2019-06-09
·
CVE-2018-9839
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
MantisBT versions 1.3.14 and earlier, 2.0.0
Description:
An issue was discovered in MantisBT where any user with REPORTER access or above can view any private issue's details, including summary, description, steps to reproduce, and additional information, when cloning it by using a crafted request on the "bug report page.php" endpoint and modifying the
m id parameter. By checking the 'Copy issue notes' and 'Copy attachments' checkboxes and completing the clone operation, this data also becomes public, except for private notes.Recommendations:
For MantisBT versions 1.3.14 and earlier, consider restricting access to the "bug report page.php" endpoint until a patch is available.
For MantisBT version 2.0.0, avoid using the
m id parameter in the "bug report page.php" endpoint until the issue is resolved.
As a temporary workaround, consider disabling the clone operation for private issues until a patch is available.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mantisbt