CVE-2025-62520
PHP vulnerability analysis and mitigation

Overview

CVE-2025-62520 affects MantisBT (Mantis Bug Tracker) versions prior to 2.27.2. The vulnerability allows any non-admin user with MANAGER role to access column configurations from private projects they don't have access to through the manageconfigcolumns_page.php interface (GitHub Advisory, MantisBT Issue).

Technical details

The vulnerability stems from insufficient access-level checks in the managecolumnscopy.php file when using the 'Copy From' action. While access controls were properly implemented for the 'Copy To' operation, the source project access verification was missing, allowing unauthorized users to retrieve column configurations from private projects (GitHub Commit). The vulnerability has a CVSS v4 base score of 5.3 (Moderate) with metrics AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N (GitHub Advisory).

Impact

The vulnerability allows unauthorized access to private project column configurations, potentially exposing sensitive information about project structure and organization. While the impact is limited to column configuration data and does not allow modification of private projects, it represents a breach of access control mechanisms (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in MantisBT version 2.27.2 by adding proper access level checks for the source project when copying column configurations. No workarounds are available for affected versions; upgrading to version 2.27.2 or later is required (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-47776HIGH8.8
  • PHPPHP
  • mantisbt/mantisbt
NoYesNov 03, 2025
CVE-2025-46556MEDIUM6.5
  • PHPPHP
  • mantisbt/mantisbt
NoYesNov 03, 2025
CVE-2025-55155MEDIUM5.4
  • PHPPHP
  • mantisbt/mantisbt
NoYesNov 03, 2025
CVE-2025-62520MEDIUM5.3
  • PHPPHP
  • mantisbt/mantisbt
NoYesNov 03, 2025
CVE-2025-64174MEDIUM4.6
  • PHPPHP
  • openmage/magento-lts
NoYesNov 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management