Information Exposure Affecting mantisbt/mantisbt package, versions <2.25.6


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-MANTISBTMANTISBT-3330771
  • published24 Feb 2023
  • disclosed23 Feb 2023
  • creditd3vpoo1

Introduced: 23 Feb 2023

CVE-2023-22476  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade mantisbt/mantisbt to version 2.25.6 or higher.

Overview

mantisbt/mantisbt is a mantis bug tracker.

Affected versions of this package are vulnerable to Information Exposure due to exposing private issues' summaries to unauthorized users. Any logged-in user allowed to perform Group Actions can get access to the _Summary_ field of private Issues (i.e. having Private view status, or belonging to a private Project) via a crafted bug_arr[] parameter in bug_actiongroup_ext.php.

CVSS Scores

version 3.1