漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API
Vulnerability Description
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in MantisBT allows users having update_bug_threshold access (UPDATER, with default settings) to edit, change view state, and modify time tracking on bugnotes belonging to other users — bypassing the default DEVELOPER (level 55) threshold required by the dedicated mc_issue_note_update() function. This vulnerability is fixed in 2.28.2.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
Mantis Bug Tracker 安全漏洞
Vulnerability Description
Mantis Bug Tracker(MantisBT)是Mantis Bug Tracker开源的一个 bug 跟踪器。 Mantis Bug Tracker 2.28.2之前版本存在安全漏洞,该漏洞源于mc_issue_update()函数允许具有update_bug_threshold权限的用户编辑其他用户的bugnotes,绕过默认的DEVELOPER阈值。以下版本受到影响:2.28.2之前版本。
CVSS Information
N/A
Vulnerability Type
N/A