CVE-2020-36192
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in the Source Integration plugin before 2.4.1 for MantisBT. An attacker can gain access to the Summary field of private Issues (either marked as Private, or part of a private Project), if they are attached to an existing Changeset. The information is visible on the view.php page, as well as on the list.php page (a pop-up on the Affected Issues id hyperlink). Additionally, if the attacker has "Update threshold" in the plugin's configuration (set to the "updater" access level by default), then they can link any Issue to a Changeset by entering the Issue's Id, even if they do not have access to it.
Se detectó un problema en el plugin Source Integration versiones anteriores a 2.4.1 para MantisBT. Un atacante puede conseguir acceso al campo Summary de Problemas privados (ya sea marcados como privados o como parte de un proyecto privado), si están adjuntos a un Changeset existente. La información está visible en la página view.php, así como en la página list.php (una ventana emergente en el hipervínculo de identificación de problemas afectados). Además, si el atacante tiene "Update threshold" en la configuración del plugin (establecido en el nivel de acceso de "updater" por defecto), entonces puede vincular cualquier Problema a un Changeset al ingresar el ID del problema, inclusive si no tiene acceso a eso
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-18 CVE Reserved
- 2021-01-18 CVE Published
- 2023-10-04 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/mantisbt-plugins/source-integration/issues/344 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mantisbt Search vendor "Mantisbt" | Source Integration Search vendor "Mantisbt" for product "Source Integration" | < 2.4.1 Search vendor "Mantisbt" for product "Source Integration" and version " < 2.4.1" | mantisbt |
Affected
|