{"id":"CVE-2020-35849","aliases":["GHSA-7j8m-fm49-xgmg"],"url":"https://o3.security/vulnerability/CVE-2020-35849","summary":"MantisBT Incorrect Authorization for bug_revision_view_page.php check","details":"An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view the Summary field of private issues, as well as bugnotes revisions, gaining access to potentially confidential information via the bugnote_id parameter.","published":"2020-12-30T19:15:13.903Z","modified":"2026-08-07T14:31:37.822103Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.01601,"percentile":0.73931,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.24.4"}],"fix":null,"references":[{"type":"REPORT","url":"https://mantisbt.org/bugs/view.php?id=27370"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:31:37.822103Z"}}