Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs.
Patch under development. The vulnerability will be fixed in MantisBT version 2.25.8.
Disable wiki integration ( $g_wiki_enable = OFF;
)
{ "nvd_published_at": "2023-10-16T22:15:12Z", "cwe_ids": [ "CWE-200", "CWE-668" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-10-17T14:20:36Z" }