First published: Wed Dec 30 2020(Updated: )
An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view the Summary field of private issues, as well as bugnotes revisions, gaining access to potentially confidential information via the bugnote_id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | <2.24.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35849 is a vulnerability in MantisBT before version 2.24.4 that allows unprivileged attackers to view the Summary field of private issues and bugnotes revisions.
CVE-2020-35849 has a severity rating of high (7.5).
CVE-2020-35849 allows unprivileged attackers to gain access to potentially confidential information by viewing the Summary field of private issues and bugnotes revisions in MantisBT.
The affected software is MantisBT versions up to and exclusive of 2.24.4.
To fix CVE-2020-35849, it is recommended to upgrade MantisBT to version 2.24.4 or later.