MantisBT may disclose project names to unauthorized users
Moderate severity
GitHub Reviewed
Published
Oct 14, 2023
in
mantisbt/mantisbt
•
Updated Nov 10, 2023
Description
Published by the National Vulnerability Database
Oct 16, 2023
Published to the GitHub Advisory Database
Oct 17, 2023
Reviewed
Oct 17, 2023
Last updated
Nov 10, 2023
Impact
Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs.
Patches
Patch under development. The vulnerability will be fixed in MantisBT version 2.25.8.
Workarounds
Disable wiki integration (
$g_wiki_enable = OFF;
)References
References