CVE-2023-22476: MantisBT: Exposure of Private issues' summary to unauthorized users
Impact Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary field of private Issues (i.e. having Private view status, or belonging to a private Project) via a crafted bugarr[] parameter in bugactiongroupext.php.
Patches The vulnerability has been fixed in MantisBT version 2.25.6.
Workarounds None
Credits Thanks to d3vpoo1 for reporting the issue.
References - https://mantisbt.org/bugs/view.php?id=31086
Other sources
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions prior to 2.25.6, due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can access to the Summary field of private Issues (i.e. having Private view status, or belonging to a private Project) via a crafted bugarr[] parameter in bugactiongroupext.php. This issue is fixed in version 2.25.6. There are no workarounds.
Affected Software
Event History
Frequently Asked Questions
What is the impact of CVE-2023-22476?
Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary field of private Issues via a crafted bug_arr[] parameter in bug_actiongroup_ext.php.
How can an attacker exploit CVE-2023-22476?
By manipulating the bug_arr[] parameter in bug_actiongroup_ext.php, an attacker can gain unauthorized access to the Summary field of private Issues.
What is the severity of CVE-2023-22476?
CVE-2023-22476 has a severity level of medium (4.3).
What software version is affected by CVE-2023-22476?
MantisBT versions up to and including 2.25.5 are affected by CVE-2023-22476.
Is there a fix available for CVE-2023-22476?
Yes, upgrading to MantisBT version 2.25.6 will fix CVE-2023-22476.