CVE-2020-25781

MEDIUM

MantisBT < 2.24.3 - Missing Authorization for Private Attachment Download

Title source: llm
STIX 2.1

Description

An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.

References (3)

Core 3

Scores

CVSS v3 4.3
EPSS 0.0093
EPSS Percentile 55.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-862
Status published
Products (2)
mantisbt/mantisbt < 2.24.3
mantisbt/mantisbt 0 - 2.24.3Packagist
Published Sep 30, 2020
Tracked Since Feb 18, 2026