First published: Thu Feb 23 2023(Updated: )
### Impact Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the _Summary_ field of private Issues (i.e. having Private view status, or belonging to a private Project) via a crafted `bug_arr[]` parameter in *bug_actiongroup_ext.php*. ### Patches The vulnerability has been fixed in MantisBT version 2.25.6. ### Workarounds None ### Credits Thanks to [d3vpoo1](https://github.com/jrckmcsb) for reporting the issue. ### References - https://mantisbt.org/bugs/view.php?id=31086
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | <2.25.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary field of private Issues via a crafted bug_arr[] parameter in bug_actiongroup_ext.php.
By manipulating the bug_arr[] parameter in bug_actiongroup_ext.php, an attacker can gain unauthorized access to the Summary field of private Issues.
CVE-2023-22476 has a severity level of medium (4.3).
MantisBT versions up to and including 2.25.5 are affected by CVE-2023-22476.
Yes, upgrading to MantisBT version 2.25.6 will fix CVE-2023-22476.