Back to CVE List

CVE-2026-34754

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Vulnerability Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-284
Source
GitHub
Vendor
composer
Product
mantisbt/mantisbt

External References

Discussion (0)

Add Comment

No comments yet. Be the first!