PT-2020-16205 · Mantisbt · Mantisbt

Pijama

·

Published

2020-09-30

·

Updated

2022-05-24

·

CVE-2020-25781

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MantisBT versions prior to 2.24.3
Description An issue allows users without access to view private issue notes to download supposedly private attachments linked to these notes by directly accessing the corresponding file download URL.
Recommendations For versions prior to 2.24.3, update to version 2.24.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the file download.php script until a patch is available.

Exploit

Fix

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25781
GHSA-XJMX-CPRH-646R

Affected Products

Mantisbt