GHSA-xjmx-cprh-646r
Dashboard / Vulnerabilities / GHSA-xjmx-cprh-646r
Summary: MantisBT unauthorized users able to access private files
Details: An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-25781, https://github.com/mantisbt/mantisbt, https://mantisbt.org/bugs/view.php?id=27039, http://github.com/mantisbt/mantisbt/commit/5595c90f11c48164331a20bb9c66098980516e93, http://github.com/mantisbt/mantisbt/commit/9de20c09e5a557e57159a61657ce62f1a4f578fe
Affected packages
Package
Name: mantisbt/mantisbt
Purl: pkg:composer/mantisbt/mantisbt
Affected ranges
Type: ECOSYSTEM
Events:
