Impact
The vulnerability allows a user to list and download attachments that they themselves uploaded to another user's issue even after that issue has been set to private. The disclosure is confined to the user's own attachments; attackers cannot obtain attachments uploaded by others. This results in a limited information‑disclosure flaw caused by improper enforcement of read‑access revocation.
Affected Systems
MantisBT versions 2.28.1 and earlier are affected; the issue was resolved in version 2.82.2.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an authenticated user who has uploaded at least one attachment to a private issue; such a user can then retrieve those attachments after the issue’s confidentiality flag is set. The impact is limited to the user’s own data, with minimal risk to other users. No public exploits are known, and the lack of a KEV listing suggests exploitation likelihood is low, though the disclosed data could expose users’ confidential material.
OpenCVE Enrichment
Github GHSA