PT-2024-25691 · Mantisbt · Mantisbt
Vboctor
·
Published
2024-05-13
·
Updated
2025-11-24
·
CVE-2024-34080
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MantisBT versions prior to 2.26.2
Description
The issue affects MantisBT, an open source issue tracker, where an issue referencing a note from another issue that the user does not have access to becomes hyperlinked. Although clicking the link results in an access denied error, some information remains accessible via the link, link label, and tooltip. This can lead to the disclosure of the note's existence, the note author's name, the note creation timestamp, and the issue ID the note belongs to.
Recommendations
For versions prior to 2.26.2, update to version 2.26.2 to resolve the issue. As a temporary workaround, consider restricting access to hyperlinked notes to minimize the risk of information disclosure.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mantisbt