Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.