PT-2025-45718 · Packagist · Mantisbt/Mantisbt

Published

2025-11-03

·

Updated

2025-11-03

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Impact

Due to insufficient access-level checks, any non-admin user having access to manage config columns page.php (typically project managers having MANAGER role) can use the Copy From action to retrieve the columns configuration from a private project they have no access to.
Access to the reverse operation ( Copy To ) is correctly controlled, i.e. it is not possible to alter the private project's configuration.

Patches

The vulnerability will be fixed in MantisBT version 2.27.2.

Workarounds

None

Credits

Thanks to d3vpoo1 for reporting the issue.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-G582-8VWR-68H2

Affected Products

Mantisbt/Mantisbt