CVE-2026-34754
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Description
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-284
Source
GitHub
Vendor
composer
Product
mantisbt/mantisbt
Discussion (0)
Add Comment
No comments yet. Be the first!