CVE-2020-25781
Published on: 09/30/2020 12:00:00 AM UTC
Last Modified on: 07/21/2021 11:39:00 AM UTC
Certain versions of Mantisbt from Mantisbt contain the following vulnerability:
An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.
- CVE-2020-25781 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 4.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
0027039: CVE-2020-25781: Access to private bug note attachments - MantisBT | Exploit Patch Vendor Advisory mantisbt.org text/html |
![]() |
Functions to check view/download ability at bugnote level · mantisbt/[email protected] · GitHub | Patch Third Party Advisory github.com text/html |
![]() |
Check ability to download attachments at bugnote level · mantisbt/[email protected] · GitHub | Patch Third Party Advisory github.com text/html |
![]() |
Related QID Numbers
- 690364 Free Berkeley Software Distribution (FreeBSD) Security Update for mantis (19259833-26b1-11eb-a239-1c697a013f4b)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Mantisbt | Mantisbt | All | All | All | All |
Application | Mantisbt | Mantisbt | All | All | All | All |
- cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*:
- cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE