Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0719 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions prior to 2.25.6, due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can access to the _Summary_ field of private Issues (i.e. having Private view status, or belonging to a private Project) via a crafted `bug_arr[]` parameter in *bug_actiongroup_ext.php*. This issue is fixed in version 2.25.6. There are no workarounds. |
Github GHSA |
GHSA-hf4x-6h87-hm79 | MantisBT may expose private issues' summaries to unauthorized users |
Mon, 10 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:06:35.048Z
Reserved: 2022-12-29T17:41:28.087Z
Link: CVE-2023-22476
Updated: 2024-08-02T10:13:48.469Z
Status : Modified
Published: 2023-02-23T19:15:13.110
Modified: 2024-11-21T07:44:52.960
Link: CVE-2023-22476
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA