Access Control Flaw in Source Integration Plugin for MantisBT
CVE-2020-36192

5.3MEDIUM

Key Information:

Vendor

Mantisbt

Vendor
CVE Published:
18 January 2021

What is CVE-2020-36192?

An issue in the Source Integration plugin for MantisBT allows attackers to access the Summary field of private Issues tied to an existing Changeset. This information can be viewed on multiple pages, including view.php and list.php. Furthermore, if the plugin's configuration grants 'Update threshold' permissions, attackers can link any Issue to a Changeset using the Issue's Id, even if they lack access to the Issue itself.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.