PT-2024-25691 · Mantisbt · Mantisbt

Vboctor

·

Published

2024-05-13

·

Updated

2025-11-24

·

CVE-2024-34080

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MantisBT versions prior to 2.26.2
Description The issue affects MantisBT, an open source issue tracker, where an issue referencing a note from another issue that the user does not have access to becomes hyperlinked. Although clicking the link results in an access denied error, some information remains accessible via the link, link label, and tooltip. This can lead to the disclosure of the note's existence, the note author's name, the note creation timestamp, and the issue ID the note belongs to.
Recommendations For versions prior to 2.26.2, update to version 2.26.2 to resolve the issue. As a temporary workaround, consider restricting access to hyperlinked notes to minimize the risk of information disclosure.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-34080
GHSA-99JC-WQMR-FF2Q

Affected Products

Mantisbt