{"id":"CVE-2025-62520","aliases":["GHSA-g582-8vwr-68h2"],"url":"https://o3.security/vulnerability/CVE-2025-62520","summary":"MantisBT unauthorized disclosure of private project column configuration","details":"### Impact\n\nDue to insufficient access-level checks, any non-admin user having access to _manage_config_columns_page.php_ (typically project managers having MANAGER role) can use the _Copy From_ action to retrieve the columns configuration from a private project they have no access to. \n\nAccess to the reverse operation (_Copy To_) is correctly controlled, i.e. it is not possible to alter the private project's configuration.\n\n### Patches\nThe vulnerability will be fixed in MantisBT version 2.27.2. \n\n### Workarounds\nNone\n\n### Credits\nThanks to [d3vpoo1](https://github.com/jrckmcsb) for reporting the issue.","published":"2025-11-04T21:31:13.261Z","modified":"2026-08-12T03:51:43.834625720Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.27.2"}],"fix":{"url":"https://github.com/mantisbt/mantisbt/commit/4fe94f45fa2baea2aeb4b65781d2009e7b4a0bf3","label":"mantisbt/mantisbt@4fe94f4"},"references":[{"type":"WEB","url":"https://mantisbt.org/bugs/view.php?id=36502"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62520.json"},{"type":"ADVISORY","url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-g582-8vwr-68h2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62520"},{"type":"FIX","url":"https://github.com/mantisbt/mantisbt/commit/4fe94f45fa2baea2aeb4b65781d2009e7b4a0bf3"},{"type":"PACKAGE","url":"https://github.com/mantisbt/mantisbt"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.834625720Z"}}