PT-2021-11698 · Mantisbt · Mantisbt

D3Vpoo1

·

Published

2021-01-29

·

Updated

2022-05-24

·

CVE-2020-29603

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: MantisBT versions prior to 2.24.4
Description: The issue allows any unprivileged logged-in user to retrieve Private Projects' names via the project id parameter in the "manage proj edit page.php" page, without having access to them.
Recommendations: For versions prior to 2.24.4, update to version 2.24.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the "manage proj edit page.php" page to minimize the risk of exploitation. Avoid using the project id parameter in the affected page until the issue is resolved.

Exploit

Fix

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29603
GHSA-QPJ5-F88Q-X7PX

Affected Products

Mantisbt