Impact
A bugnote author can view the Revisions page of a private issue after their access to that issue has been revoked, exposing confidential issue metadata. The flaw enables unauthorized disclosure of sensitive data through a data‑exposure weakness (CWE-200). An attacker who previously had legitimate access to the issue can exploit the bug to read information that should no longer be visible, potentially revealing proprietary or privileged data within the issue.
Affected Systems
The vulnerability affects Mantis Bug Tracker 2.28.1 and earlier. Administrators and developers using these versions should verify whether their installations include any private issues with bugnote notes.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attacks require prior legitimate access to the affected issue; external exploitation without such access is unlikely. The threat primarily concerns users who have temporarily held author rights to a private issue, enabling them to read that issue’s metadata after revocation. Given the moderate CVSS score and limited attack vector, organizations should monitor for inadvertent data exposure and apply the patch promptly.
OpenCVE Enrichment
Github GHSA