MantisBT vulnerable to information disclosure with user profiles
Moderate severity
GitHub Reviewed
Published
Sep 28, 2024
in
mantisbt/mantisbt
•
Updated Sep 30, 2024
Description
Published by the National Vulnerability Database
Sep 30, 2024
Published to the GitHub Advisory Database
Sep 30, 2024
Reviewed
Sep 30, 2024
Last updated
Sep 30, 2024
Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles.
Impact
Disclosure of private system profiles: Platform, OS, OS version, Description.
Patches
Work in progress
Workarounds
None
References
https://mantisbt.org/bugs/view.php?id=34640
References