Impact
Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs.
Patches
The vulnerability has been fixed in MantisBT version 2.25.8 (https://github.com/mantisbt/mantisbt/commit/65c44883f9d24f3ccef066fb523c93d8fdd7afc1).
Workarounds
Disable wiki integration ( $g_wiki_enable = OFF;)
References
References:- https://github.com/mantisbt/mantisbt/security/advisories/GHSA-v642-mh27-8j6m
- https://nvd.nist.gov/vuln/detail/CVE-2023-44394
- https://github.com/mantisbt/mantisbt/commit/65c44883f9d24f3ccef066fb523c93d8fdd7afc1
- https://mantisbt.org/bugs/view.php?id=32981
- https://github.com/advisories/GHSA-v642-mh27-8j6m